PT-2025-51625 · Linux+3 · Linux Kernel+3

CVE-2025-68212

·

Published

2025-10-13

·

Updated

2026-08-19

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A flaw exists in the Linux kernel's handling of mount string statistics within the statmount string() function. Specifically, the offp variable, intended to track the output offset, remains uninitialized in certain scenarios involving STATMOUNT MNT UIDMAP and STATMOUNT MNT GIDMAP flags. This uninitialized state can lead to a potential dereference error when the offp variable is subsequently used. The issue arises because these flags directly set struct fields instead of utilizing offp as intended, causing inconsistency in the code path.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Access of Uninitialized Pointer

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-10637
CVE-2025-68212
USN-8094-1
USN-8094-2
USN-8094-3
USN-8094-4
USN-8094-5
USN-8152-1

Affected Products

Debian
Linuxmint
Linux Kernel
Ubuntu