cbcvebase.
CVE-2025-68764
published 2026-01-05

CVE-2025-68764: In the Linux kernel, the following vulnerability has been resolved: NFS: Automounted filesystems should inherit ro,noexec,nodev,sync flags When a filesystem is…

PriorityP337high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.13%
2.7th percentile
In the Linux kernel, the following vulnerability has been resolved: NFS: Automounted filesystems should inherit ro,noexec,nodev,sync flags When a filesystem is being automounted, it needs to preserve the user-set superblock mount options, such as the "ro" flag.

Affected

45 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
debianlinux-6.1< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
linuxlinux
linuxlinux>= f2aedb713c284429987dc66c7aaf38decfc8da2a < a3dc6c40bcab1a888d5c0d134ccc0746b4c98929a3dc6c40bcab1a888d5c0d134ccc0746b4c98929
linuxlinux>= f2aedb713c284429987dc66c7aaf38decfc8da2a < ba1495aefd22fcf0746a2a3025c95d766d7cde4dba1495aefd22fcf0746a2a3025c95d766d7cde4d
linuxlinux>= f2aedb713c284429987dc66c7aaf38decfc8da2a < c09070b4def1b34e473a746c6a5331ccb80902c1c09070b4def1b34e473a746c6a5331ccb80902c1
linuxlinux>= f2aedb713c284429987dc66c7aaf38decfc8da2a < dce10c59211e5cd763a62ea01e79b82a629811e3dce10c59211e5cd763a62ea01e79b82a629811e3
linuxlinux>= f2aedb713c284429987dc66c7aaf38decfc8da2a < 612cc98698d667df804792f0c47d4e501e66da29612cc98698d667df804792f0c47d4e501e66da29
linuxlinux>= f2aedb713c284429987dc66c7aaf38decfc8da2a < 4b296944e632cf4c6a4cc8e2585c6451eae47b1b4b296944e632cf4c6a4cc8e2585c6451eae47b1b
linuxlinux>= f2aedb713c284429987dc66c7aaf38decfc8da2a < df9b003a2ecacc7218486fbb31fe008c93097d5fdf9b003a2ecacc7218486fbb31fe008c93097d5f
linuxlinux>= f2aedb713c284429987dc66c7aaf38decfc8da2a < 8675c69816e4276b979ff475ee5fac4688f801258675c69816e4276b979ff475ee5fac4688f80125
linuxlinux_kernel>= 0 < 5.10.249-15.10.249-1
linuxlinux_kernel>= 0 < 6.1.162-16.1.162-1
linuxlinux_kernel>= 0 < 6.12.63-16.12.63-1
linuxlinux_kernel>= 0 < 6.17.13-16.17.13-1
linuxlinux_kernel>= 0 < 5.15.0-173.1835.15.0-173.183
linuxlinux_kernel>= 0 < 6.17.0-19.196.17.0-19.19
linuxlinux_kernel>= 5.11.0 < 5.15.1985.15.198
linuxlinux_kernel>= 5.16.0 < 6.1.1606.1.160
linuxlinux_kernel>= 5.6.0 < 5.10.2485.10.248
linuxlinux_kernel>= 6.13.0 < 6.17.136.17.13
linuxlinux_kernel>= 6.18.0 < 6.18.26.18.2
linuxlinux_kernel>= 6.2.0 < 6.6.1206.6.120
linuxlinux_kernel>= 6.7.0 < 6.12.636.12.63
ubuntulinux-aws-fips

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_redhat6.1MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.