CVE-2025-68185
EPSS 0.06%發布日:2025/12/16修改日:2026/4/28
描述
In the Linux kernel, the following vulnerability has been resolved: nfs4_setup_readdir(): insufficient locking for ->d_parent->d_inode dereferencing Theoretically it's an oopsable race, but I don't believe one can manage to hit it on real hardware; might become doable on a KVM, but it still won't be easy to attack. Anyway, it's easy to deal with - since xdr_encode_hyper() is just a call of put_unaligned_be64(), we can put that under ->d_lock and be done with that.
受影響套件(2)
- Debian/linuxfrom 0, < 5.10.247-1
- Debian/linux-6.1from 0, < 6.1.159-1~deb11u1