cbcvebase.
CVE-2025-68788
published 2026-01-13

CVE-2025-68788: In the Linux kernel, the following vulnerability has been resolved: fsnotify: do not generate ACCESS/MODIFY events on child for special files inotify/fanotify…

PriorityP426high7.8
EPSS
0.18%
7.5th percentile
In the Linux kernel, the following vulnerability has been resolved: fsnotify: do not generate ACCESS/MODIFY events on child for special files inotify/fanotify do not allow users with no read access to a file to subscribe to events (e.g. IN_ACCESS/IN_MODIFY), but they do allow the same user to subscribe for watching events on children when the user has access to the parent directory (e.g. /dev). Users with no read access to a file but with read access to its parent directory can still stat the file and see if it was accessed/modified via atime/mtime change. The same is not true for special files (e.g. /dev/null). Users will not generally observe atime/mtime changes when other users read/write to special files, only when someone sets atime/mtime via utimensat(). Align fsnotify events with this stat behavior and do not generate ACCESS/MODIFY events to parent watchers on read/write of special files. The events are still generated to parent watchers on utimensat(). This closes some side-channels that could be possibly used for information exfiltration [1]. [1] https://snee.la/pdf/pubs/file-notification-attacks.pdf

Affected

51 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
debianlinux-6.1< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
linuxlinux
linuxlinux>= 72acc854427948efed7a83da27f7dc3239ac9afc < df2711544b050aba703e6da418c53c7dc5d443cadf2711544b050aba703e6da418c53c7dc5d443ca
linuxlinux>= 72acc854427948efed7a83da27f7dc3239ac9afc < 859bdf438f01d9aa7f84b09c1202d548c7cad9e8859bdf438f01d9aa7f84b09c1202d548c7cad9e8
linuxlinux>= 72acc854427948efed7a83da27f7dc3239ac9afc < 6a7d7d96eeeab7af2bd01afbb3d9878a11a13d916a7d7d96eeeab7af2bd01afbb3d9878a11a13d91
linuxlinux>= 72acc854427948efed7a83da27f7dc3239ac9afc < e0643d46759db8b84c0504a676043e5e341b6c81e0643d46759db8b84c0504a676043e5e341b6c81
linuxlinux>= 72acc854427948efed7a83da27f7dc3239ac9afc < 82f7416bcbd951549e758d15fc1a96a5afc2e90082f7416bcbd951549e758d15fc1a96a5afc2e900
linuxlinux>= 72acc854427948efed7a83da27f7dc3239ac9afc < 7a93edb23bcf07a3aaf8b598edfc2faa8fbcc0b67a93edb23bcf07a3aaf8b598edfc2faa8fbcc0b6
linuxlinux>= 72acc854427948efed7a83da27f7dc3239ac9afc < 635bc4def026a24e071436f4f356ea08c0eed6ff635bc4def026a24e071436f4f356ea08c0eed6ff
linuxlinux_kernel>= 0 < 5.10.249-15.10.249-1
linuxlinux_kernel>= 0 < 6.1.162-16.1.162-1
linuxlinux_kernel>= 0 < 6.12.69-16.12.69-1
linuxlinux_kernel>= 0 < 6.18.3-16.18.3-1
linuxlinux_kernel>= 0 < 5.15.0-173.1835.15.0-173.183
linuxlinux_kernel>= 2.6.36 < 5.10.2485.10.248
linuxlinux_kernel>= 5.11.0 < 5.15.1985.15.198
linuxlinux_kernel>= 5.16.0 < 6.1.1606.1.160
linuxlinux_kernel>= 6.13.0 < 6.18.36.18.3
linuxlinux_kernel>= 6.2.0 < 6.6.1206.6.120
linuxlinux_kernel>= 6.7.0 < 6.12.646.12.64
ubuntulinux-aws
ubuntulinux-aws-6.17
ubuntulinux-aws-fips
ubuntulinux-azure

CVSS provenance

osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_redhat2.5LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.