PT-2025-51689 · Linux+5 · Linux Kernel+5
CVE-2025-68285
·
Published
2025-11-03
·
Updated
2026-08-30
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to 6.14.0-rc2-build2+ #1266
Description
The Linux kernel contains a flaw in libceph related to a potential use-after-free condition within the
have mon and osd map() function. The issue arises from a race condition in the ceph open session() wait loop, where the client may receive a new monmap or osdmap shortly after the initial map is freed. This can lead to dereferencing an already freed map when checking the epoch values of the monmap and osdmap. The problem is reproducible with generic/395 and generic/397 when KASAN is enabled. The vulnerability occurs due to the lack of appropriate locking when accessing map epoch values.Recommendations
Update to a version newer than 6.14.0-rc2-build2+ #1266.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Debian
Linuxmint
Linux Kernel
Rocky Linux
Ubuntu
Libceph