cbcvebase.
CVE-2025-68767
published 2026-01-13

CVE-2025-68767: In the Linux kernel, the following vulnerability has been resolved: hfsplus: Verify inode mode when loading from disk syzbot is reporting that S_IFMT bits of…

PriorityP421high7.8
EPSS
0.17%
6.9th percentile
In the Linux kernel, the following vulnerability has been resolved: hfsplus: Verify inode mode when loading from disk syzbot is reporting that S_IFMT bits of inode->i_mode can become bogus when the S_IFMT bits of the 16bits "mode" field loaded from disk are corrupted. According to [1], the permissions field was treated as reserved in Mac OS 8 and 9. According to [2], the reserved field was explicitly initialized with 0, and that field must remain 0 as long as reserved. Therefore, when the "mode" field is not 0 (i.e. no longer reserved), the file must be S_IFDIR if dir == 1, and the file must be one of S_IFREG/S_IFLNK/S_IFCHR/ S_IFBLK/S_IFIFO/S_IFSOCK if dir == 0.

Affected

51 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
debianlinux-6.1< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
linuxlinux
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 6f768724aabd5b321c5b8f15acdca11e4781cf326f768724aabd5b321c5b8f15acdca11e4781cf32
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < d92333c7a35856e419500e7eed72dac1afa404a5d92333c7a35856e419500e7eed72dac1afa404a5
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 001f44982587ad462b3002ee40c75e8df67d597d001f44982587ad462b3002ee40c75e8df67d597d
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 05ec9af3cc430683c97f76027e1c55ac6fd25c5905ec9af3cc430683c97f76027e1c55ac6fd25c59
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < edfb2e602b5ba5ca6bf31cbac20b366efb72b156edfb2e602b5ba5ca6bf31cbac20b366efb72b156
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 91f114bffa36ce56d0e1f60a0a44fc09baaefc7991f114bffa36ce56d0e1f60a0a44fc09baaefc79
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 005d4b0d33f6b4a23d382b7930f7a96b95b01f39005d4b0d33f6b4a23d382b7930f7a96b95b01f39
linuxlinux_kernel>= 0 < 5.10.249-15.10.249-1
linuxlinux_kernel>= 0 < 6.1.162-16.1.162-1
linuxlinux_kernel>= 0 < 6.12.69-16.12.69-1
linuxlinux_kernel>= 0 < 6.18.3-16.18.3-1
linuxlinux_kernel>= 0 < 5.15.0-173.1835.15.0-173.183
linuxlinux_kernel>= 2.6.12 < 5.10.2485.10.248
linuxlinux_kernel>= 5.11.0 < 5.15.1985.15.198
linuxlinux_kernel>= 5.16.0 < 6.1.1606.1.160
linuxlinux_kernel>= 6.13.0 < 6.18.36.18.3
linuxlinux_kernel>= 6.2.0 < 6.6.1206.6.120
linuxlinux_kernel>= 6.7.0 < 6.12.646.12.64
ubuntulinux-aws
ubuntulinux-aws-6.17
ubuntulinux-aws-fips
ubuntulinux-azure

CVSS provenance

osv7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.