cbcvebase.
CVE-2025-68786
published 2026-01-13

CVE-2025-68786: In the Linux kernel, the following vulnerability has been resolved: ksmbd: skip lock-range check on equal size to avoid size==0 underflow When size equals the…

PriorityP420medium6.4
EPSS
0.17%
6.5th percentile
In the Linux kernel, the following vulnerability has been resolved: ksmbd: skip lock-range check on equal size to avoid size==0 underflow When size equals the current i_size (including 0), the code used to call check_lock_range(filp, i_size, size - 1, WRITE), which computes `size - 1` and can underflow for size==0. Skip the equal case.

Affected

44 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
debianlinux-6.1< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
linuxlinux
linuxlinux>= f44158485826c076335d6860d35872271a83791d < 52fcbb92e0d3acfd1448b2a43b6595d540da529552fcbb92e0d3acfd1448b2a43b6595d540da5295
linuxlinux>= f44158485826c076335d6860d35872271a83791d < da29cd197246c85c0473259f1cad897d9d28faeada29cd197246c85c0473259f1cad897d9d28faea
linuxlinux>= f44158485826c076335d6860d35872271a83791d < a6f4cfa3783804336491e0edcb250c25f9b59d33a6f4cfa3783804336491e0edcb250c25f9b59d33
linuxlinux>= f44158485826c076335d6860d35872271a83791d < 571204e4758a528fbd67330bd4b0dfbdafb33dd8571204e4758a528fbd67330bd4b0dfbdafb33dd8
linuxlinux>= f44158485826c076335d6860d35872271a83791d < 5d510ac31626ed157d2182149559430350cf21045d510ac31626ed157d2182149559430350cf2104
linuxlinux_kernel>= 0 < 6.1.162-16.1.162-1
linuxlinux_kernel>= 0 < 6.12.69-16.12.69-1
linuxlinux_kernel>= 0 < 6.18.3-16.18.3-1
linuxlinux_kernel>= 5.15.0 < 6.1.1606.1.160
linuxlinux_kernel>= 6.13.0 < 6.18.36.18.3
linuxlinux_kernel>= 6.2.0 < 6.6.1206.6.120
linuxlinux_kernel>= 6.7.0 < 6.12.646.12.64
ubuntulinux-aws
ubuntulinux-aws-6.17
ubuntulinux-aws-fips
ubuntulinux-azure
ubuntulinux-azure-6.17
ubuntulinux-azure-6.8
ubuntulinux-azure-fips
ubuntulinux-fips
ubuntulinux-gcp
ubuntulinux-gcp-6.17
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.