cbcvebase.
CVE-2025-68733
published 2025-12-24

CVE-2025-68733: In the Linux kernel, the following vulnerability has been resolved: smack: fix bug: unprivileged task can create labels If an unprivileged task is allowed to…

PriorityP419high7.8
EPSS
0.18%
7.3th percentile
In the Linux kernel, the following vulnerability has been resolved: smack: fix bug: unprivileged task can create labels If an unprivileged task is allowed to relabel itself (/smack/relabel-self is not empty), it can freely create new labels by writing their names into own /proc/PID/attr/smack/current This occurs because do_setattr() imports the provided label in advance, before checking "relabel-self" list. This change ensures that the "relabel-self" list is checked before importing the label.

Affected

48 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
debianlinux-6.1< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
linuxlinux
linuxlinux>= 38416e53936ecf896948fdeffc36b76979117952 < c80173233014a360c13fa5cc79d36bfe6e53a8edc80173233014a360c13fa5cc79d36bfe6e53a8ed
linuxlinux>= 38416e53936ecf896948fdeffc36b76979117952 < 6b1e45e13546c9ea0b1d99097993ac0aafae90b16b1e45e13546c9ea0b1d99097993ac0aafae90b1
linuxlinux>= 38416e53936ecf896948fdeffc36b76979117952 < 4a7a7621619a366712fb9cefcb6e69f956c247ce4a7a7621619a366712fb9cefcb6e69f956c247ce
linuxlinux>= 38416e53936ecf896948fdeffc36b76979117952 < f8fd5491100f920847a3338d5fba22db19c72773f8fd5491100f920847a3338d5fba22db19c72773
linuxlinux>= 38416e53936ecf896948fdeffc36b76979117952 < ac9fce2efabad37c338aac86fbe100f77a080e59ac9fce2efabad37c338aac86fbe100f77a080e59
linuxlinux>= 38416e53936ecf896948fdeffc36b76979117952 < 64aa81250171b6bb6803e97ea7a5d73bfa061f6e64aa81250171b6bb6803e97ea7a5d73bfa061f6e
linuxlinux>= 38416e53936ecf896948fdeffc36b76979117952 < 60e8d49989410a7ade60f5dadfcd979c117d05c060e8d49989410a7ade60f5dadfcd979c117d05c0
linuxlinux>= 38416e53936ecf896948fdeffc36b76979117952 < c147e13ea7fe9f118f8c9ba5e96cbd644b00d6b3c147e13ea7fe9f118f8c9ba5e96cbd644b00d6b3
linuxlinux_kernel>= 0 < 5.10.249-15.10.249-1
linuxlinux_kernel>= 0 < 6.1.162-16.1.162-1
linuxlinux_kernel>= 0 < 6.12.63-16.12.63-1
linuxlinux_kernel>= 0 < 6.17.13-16.17.13-1
linuxlinux_kernel>= 0 < 5.15.0-173.1835.15.0-173.183
linuxlinux_kernel>= 0 < 6.17.0-19.196.17.0-19.19
linuxlinux_kernel>= 4.4.0 < 5.10.2485.10.248
linuxlinux_kernel>= 5.11.0 < 5.15.1985.15.198
linuxlinux_kernel>= 5.16.0 < 6.1.1606.1.160
linuxlinux_kernel>= 6.13.0 < 6.17.136.17.13
linuxlinux_kernel>= 6.18.0 < 6.18.26.18.2
linuxlinux_kernel>= 6.2.0 < 6.6.1206.6.120
linuxlinux_kernel>= 6.7.0 < 6.12.636.12.63
msrcazl3_kernel_6.6.117.1-1_on_azure_linux_3.0

CVSS provenance

osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_msrc5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.