Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2025-68185

Gravedad:
Pendiente de análisis
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
16/12/2025
Última modificación:
18/12/2025

Descripción

*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> nfs4_setup_readdir(): insufficient locking for -&gt;d_parent-&gt;d_inode dereferencing<br /> <br /> Theoretically it&amp;#39;s an oopsable race, but I don&amp;#39;t believe one can manage<br /> to hit it on real hardware; might become doable on a KVM, but it still<br /> won&amp;#39;t be easy to attack.<br /> <br /> Anyway, it&amp;#39;s easy to deal with - since xdr_encode_hyper() is just a call of<br /> put_unaligned_be64(), we can put that under -&gt;d_lock and be done with that.

Impacto