cbcvebase.
CVE-2025-68727
published 2025-12-24

CVE-2025-68727: In the Linux kernel, the following vulnerability has been resolved: ntfs3: Fix uninit buffer allocated by __getname() Fix uninit errors caused after buffer…

PriorityP419high7.8
EPSS
0.17%
6.8th percentile
In the Linux kernel, the following vulnerability has been resolved: ntfs3: Fix uninit buffer allocated by __getname() Fix uninit errors caused after buffer allocation given to 'de'; by initializing the buffer with zeroes. The fix was found by using KMSAN.

Affected

44 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
debianlinux-6.1< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
linuxlinux
linuxlinux>= 78ab59fee07f22464f32eafebab2bd97ba94ff2d < 90e23db1a85956026999c18e76f402542cb004da90e23db1a85956026999c18e76f402542cb004da
linuxlinux>= 78ab59fee07f22464f32eafebab2bd97ba94ff2d < 53f4d6cb97096590410f3719f75cdf9fc5120f3753f4d6cb97096590410f3719f75cdf9fc5120f37
linuxlinux>= 78ab59fee07f22464f32eafebab2bd97ba94ff2d < dcb5e3cd96b77d52bb65988e4c914636a6d4fdd9dcb5e3cd96b77d52bb65988e4c914636a6d4fdd9
linuxlinux>= 78ab59fee07f22464f32eafebab2bd97ba94ff2d < 4b1fd82848fdf0e01b3320815b261006c1722c3e4b1fd82848fdf0e01b3320815b261006c1722c3e
linuxlinux>= 78ab59fee07f22464f32eafebab2bd97ba94ff2d < d88d4b455b6794f48d7adad52593f1700c7bd50ed88d4b455b6794f48d7adad52593f1700c7bd50e
linuxlinux>= 78ab59fee07f22464f32eafebab2bd97ba94ff2d < b40a4eb4a0543d49686a6e693745009dac3b86a9b40a4eb4a0543d49686a6e693745009dac3b86a9
linuxlinux>= 78ab59fee07f22464f32eafebab2bd97ba94ff2d < 9948dcb2f7b5a1bf8e8710eafaf6016e00be3ad69948dcb2f7b5a1bf8e8710eafaf6016e00be3ad6
linuxlinux_kernel>= 0 < 6.1.162-16.1.162-1
linuxlinux_kernel>= 0 < 6.12.63-16.12.63-1
linuxlinux_kernel>= 0 < 6.17.13-16.17.13-1
linuxlinux_kernel>= 0 < 5.15.0-173.1835.15.0-173.183
linuxlinux_kernel>= 0 < 6.17.0-19.196.17.0-19.19
linuxlinux_kernel>= 5.15.0 < 5.15.1985.15.198
linuxlinux_kernel>= 5.16.0 < 6.1.1606.1.160
linuxlinux_kernel>= 6.13.0 < 6.17.136.17.13
linuxlinux_kernel>= 6.18.0 < 6.18.26.18.2
linuxlinux_kernel>= 6.2.0 < 6.6.1206.6.120
linuxlinux_kernel>= 6.7.0 < 6.12.636.12.63
msrcazl3_kernel_6.6.117.1-1_on_azure_linux_3.0
msrcazl3_kernel_6.6.119.3-1_on_azure_linux_3.0
ubuntulinux-aws-fips
ubuntulinux-azure

CVSS provenance

osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_msrc3.3LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.