CVE-2025-68357
published 2025-12-24CVE-2025-68357: In the Linux kernel, the following vulnerability has been resolved: iomap: allocate s_dio_done_wq for async reads as well Since commit 222f2c7c6d14 ("iomap…
PriorityP421medium5.5
EPSS
0.22%
12.2th percentile
In the Linux kernel, the following vulnerability has been resolved:
iomap: allocate s_dio_done_wq for async reads as well
Since commit 222f2c7c6d14 ("iomap: always run error completions in user
context"), read error completions are deferred to s_dio_done_wq. This
means the workqueue also needs to be allocated for async reads.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.18.3-1 (forky) | linux 6.18.3-1 (forky) |
| linux | linux | — | — |
| linux | linux | >= 3b5f35085f8159894a0963e2c877527a885201ac < 51297686e00f4d5d941b0f20f12b2f12879d753c | 51297686e00f4d5d941b0f20f12b2f12879d753c |
| linux | linux | >= 6.12.63 < 6.12.64 | 6.12.64 |
| linux | linux | >= 6.17.13 < 6.18 | 6.18 |
| linux | linux | >= 6.6.120 < 6.6.130 | 6.6.130 |
| linux | linux | >= 74c0c1af04ee6982b47237b1c12cff63ffb14460 < c67775cf0da2407f113c1229e350758f4dca0f51 | c67775cf0da2407f113c1229e350758f4dca0f51 |
| linux | linux | >= ddb4873286e03e193c5a3bebb5fc6fa820e9ee3a < 7fd8720dff2d9c70cf5a1a13b7513af01952ec02 | 7fd8720dff2d9c70cf5a1a13b7513af01952ec02 |
| linux | linux | >= e3676761efb20564297250f000cbbd2187de2601 < bfc717be833fd9ee41443fde2dea0352a7fca333 | bfc717be833fd9ee41443fde2dea0352a7fca333 |
| linux | linux_kernel | >= 0 < 6.12.69-1 | 6.12.69-1 |
| linux | linux_kernel | >= 0 < 6.18.3-1 | 6.18.3-1 |
| linux | linux_kernel | >= 6.12.63 < 6.12.64 | 6.12.64 |
| linux | linux_kernel | >= 6.6.120 < 6.6.130 | 6.6.130 |
| msrc | azl3_kernel_6.6.117.1-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_kernel_6.6.119.3-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_kernel_6.6.126.1-1_on_azure_linux_3.0 | — | — |
CVSS provenance
vendor_msrc5.5MEDIUM
vendor_redhat5.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: iomap: allocate s_dio_done_wq for async reads as well
vendor_redhat·2025-12-24·CVSS 5.5
CVE-2025-68357 [LOW] kernel: iomap: allocate s_dio_done_wq for async reads as well
kernel: iomap: allocate s_dio_done_wq for async reads as well
In the Linux kernel, the following vulnerability has been resolved:
iomap: allocate s_dio_done_wq for async reads as well
Since commit 222f2c7c6d14 ("iomap: always run error completions in user
context"), read error completions are deferred to s_dio_done_wq. This
means the workqueue also needs to be allocated for async reads.
Package: kernel (Red Hat Enterprise Linux 10) - Fix deferred
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 7) - Not affected
Package: kernel (Red Hat Enterprise Linux 8) - Fix deferred
Package: kernel-rt (Red Hat Enterprise Linux 8) - Fix deferred
Package: kernel (Red Hat Enterprise
Microsoft
iomap: allocate s_dio_done_wq for async reads as well
vendor_msrc·2025-12-09·CVSS 5.5
CVE-2025-68357 [MEDIUM] iomap: allocate s_dio_done_wq for async reads as well
iomap: allocate s_dio_done_wq for async reads as well
Mariner: Mariner
Linux: Linux
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade
Debian
CVE-2025-68357: linux - In the Linux kernel, the following vulnerability has been resolved: iomap: allo...
vendor_debian·2025
CVE-2025-68357 [LOW] CVE-2025-68357: linux - In the Linux kernel, the following vulnerability has been resolved: iomap: allo...
In the Linux kernel, the following vulnerability has been resolved: iomap: allocate s_dio_done_wq for async reads as well Since commit 222f2c7c6d14 ("iomap: always run error completions in user context"), read error completions are deferred to s_dio_done_wq. This means the workqueue also needs to be allocated for async reads.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 6.18.3-1)
sid: resolved (fixed in 6.18.3-1)
trixie: resolved (fixed in 6.12.69-1)
OSV
iomap: allocate s_dio_done_wq for async reads as well
osv·2025-12-24
CVE-2025-68357 iomap: allocate s_dio_done_wq for async reads as well
iomap: allocate s_dio_done_wq for async reads as well
In the Linux kernel, the following vulnerability has been resolved:
iomap: allocate s_dio_done_wq for async reads as well
Since commit 222f2c7c6d14 ("iomap: always run error completions in user
context"), read error completions are deferred to s_dio_done_wq. This
means the workqueue also needs to be allocated for async reads.
GHSA
GHSA-6998-95jp-6xx2: In the Linux kernel, the following vulnerability has been resolved:
iomap: allocate s_dio_done_wq for async reads as well
Since commit 222f2c7c6d14
ghsa_unreviewed·2025-12-24
CVE-2025-68357 GHSA-6998-95jp-6xx2: In the Linux kernel, the following vulnerability has been resolved:
iomap: allocate s_dio_done_wq for async reads as well
Since commit 222f2c7c6d14
In the Linux kernel, the following vulnerability has been resolved:
iomap: allocate s_dio_done_wq for async reads as well
Since commit 222f2c7c6d14 ("iomap: always run error completions in user
context"), read error completions are deferred to s_dio_done_wq. This
means the workqueue also needs to be allocated for async reads.
OSV
CVE-2025-68357: In the Linux kernel, the following vulnerability has been resolved: iomap: allocate s_dio_done_wq for async reads as well Since commit 222f2c7c6d14 ("
osv·2025-12-24
CVE-2025-68357 CVE-2025-68357: In the Linux kernel, the following vulnerability has been resolved: iomap: allocate s_dio_done_wq for async reads as well Since commit 222f2c7c6d14 ("
In the Linux kernel, the following vulnerability has been resolved: iomap: allocate s_dio_done_wq for async reads as well Since commit 222f2c7c6d14 ("iomap: always run error completions in user context"), read error completions are deferred to s_dio_done_wq. This means the workqueue also needs to be allocated for async reads.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2025-68357 kernel: iomap: allocate s_dio_done_wq for async reads as well
bugzilla·2025-12-24
CVE-2025-68357 [MEDIUM] CVE-2025-68357 kernel: iomap: allocate s_dio_done_wq for async reads as well
CVE-2025-68357 kernel: iomap: allocate s_dio_done_wq for async reads as well
In the Linux kernel, the following vulnerability has been resolved:
iomap: allocate s_dio_done_wq for async reads as well
Since commit 222f2c7c6d14 ("iomap: always run error completions in user
context"), read error completions are deferred to s_dio_done_wq. This
means the workqueue also needs to be allocated for async reads.
Discussion:
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2025122456-CVE-2025-68357-2d18@gregkh/T
Wiz
CVE-2025-68357 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz
CVE-2025-68357 CVE-2025-68357 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-68357 :
Linux Kernel vulnerability analysis and mitigation
In the Linux kernel, the following vulnerability has been resolved:
iomap: allocate s_dio_done_wq for async reads as well
Since commit 222f2c7c6d14 ("iomap: always run error completions in user
context"), read error completions are deferred to s_dio_done_wq. This
means the workqueue also needs to be allocated for async reads.
Source : NVD
## 5.5
Score
Published December 24, 2025
Severity MEDIUM
CNA Score N/A
Affected Technologies
Linux Kernel
CBL Mariner
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 1.6
Exploitation Probability (EPSS) N/A
Affected packages and libraries
kernel-64k
kernel-rt-devel
Sources
2025-12-24
Published