cbcvebase.
CVE-2025-68820
published 2026-01-13

CVE-2025-68820: In the Linux kernel, the following vulnerability has been resolved: ext4: xattr: fix null pointer deref in ext4_raw_inode() If ext4_get_inode_loc() fails (e.g…

PriorityP418high7.8
EPSS
0.18%
8.2th percentile
In the Linux kernel, the following vulnerability has been resolved: ext4: xattr: fix null pointer deref in ext4_raw_inode() If ext4_get_inode_loc() fails (e.g. if it returns -EFSCORRUPTED), iloc.bh will remain set to NULL. Since ext4_xattr_inode_dec_ref_all() lacks error checking, this will lead to a null pointer dereference in ext4_raw_inode(), called right after ext4_get_inode_loc(). Found by Linux Verification Center (linuxtesting.org) with SVACE.

Affected

62 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
debianlinux-6.1< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 362a90cecd36e8a5c415966d0b75b04a0270e4dd < b5d942922182e82724b7152cb998f540132885ecb5d942922182e82724b7152cb998f540132885ec
linuxlinux>= 5.10.237 < 5.10.2485.10.248
linuxlinux>= 5.15.181 < 5.15.1985.15.198
linuxlinux>= 5.4.293 < 5.55.5
linuxlinux>= 6.1.135 < 6.1.1606.1.160
linuxlinux>= 6.12.24 < 6.12.646.12.64
linuxlinux>= 6.13.12 < 6.146.14
linuxlinux>= 6.14.3 < 6.156.15
linuxlinux>= 6.6.88 < 6.6.1206.6.120
linuxlinux>= 76c365fa7e2a8bb85f0190cdb4b8cdc99b2fdce3 < b72a3476f0c97d02f63a6e9fff127348d55436f6b72a3476f0c97d02f63a6e9fff127348d55436f6
linuxlinux>= c8e008b60492cf6fd31ef127aea6d02fd3d314cd < ce5f54c065a4a7cbb92787f4f140917112350142ce5f54c065a4a7cbb92787f4f140917112350142
linuxlinux>= c8e008b60492cf6fd31ef127aea6d02fd3d314cd < b97cb7d6a051aa6ebd57906df0e26e9e36c26d14b97cb7d6a051aa6ebd57906df0e26e9e36c26d14
linuxlinux>= cf9291a3449b04688b81e32621e88de8f4314b54 < 190ad0f22ba49f1101182b80e3af50ca2ddfe72f190ad0f22ba49f1101182b80e3af50ca2ddfe72f
linuxlinux>= eb59cc31b6ea076021d14b04e7faab1636b87d0e < 5b154e901fda2e98570b8f426a481f5740097dc25b154e901fda2e98570b8f426a481f5740097dc2
linuxlinux>= f737418b6de31c962c7192777ee4018906975383 < 3d8d22e75f7edfa0b30ff27330fd6a1285d594c33d8d22e75f7edfa0b30ff27330fd6a1285d594c3
linuxlinux_kernel>= 0 < 5.10.249-15.10.249-1
linuxlinux_kernel>= 0 < 6.1.162-16.1.162-1
linuxlinux_kernel>= 0 < 6.12.69-16.12.69-1
linuxlinux_kernel>= 0 < 6.18.3-16.18.3-1

CVSS provenance

osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_redhat5.5LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.