PT-2025-51701 · Linux+4 · Linux Kernel+4

CVE-2025-68297

·

Published

2025-11-13

·

Updated

2026-08-30

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.17.0-rc7+
Description The Linux kernel contains a flaw in the Ceph implementation, specifically within the ceph con v2 try read function. This issue can lead to a crash when processing sparse reads for fscrypt-encrypted directories using the Ceph msgr2 protocol in secure mode. The crash can be triggered by mounting a Ceph filesystem, creating a directory, copying a file into it, encrypting the directory, unlocking it, and then attempting to read the file. The root cause is a general protection fault, potentially due to a non-canonical address.
Recommendations Update to a version of the Linux kernel that contains the fix for this issue.

Exploit

Fix

Use of Uninitialized Resource

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-11986
CVE-2025-68297
ECHO-568F-2036-225B
MGASA-2026-0017
MGASA-2026-0018
OESA-2026-1759
OESA-2026-1760
OESA-2026-1761
OPENSUSE-SU-2026:20287-1
SUSE-SU-2026:0447-1
SUSE-SU-2026:0472-1
SUSE-SU-2026:0587-1
SUSE-SU-2026:20477-1
SUSE-SU-2026:20498-1
SUSE-SU-2026:20555-1
SUSE-SU-2026:20570-1
SUSE-SU-2026:20599-1
SUSE-SU-2026:20615-1
SUSE-SU-2026:20845-1
SUSE-SU-2026:20876-1
USN-8094-1
USN-8094-2
USN-8094-3
USN-8094-4
USN-8094-5
USN-8095-1
USN-8095-2
USN-8095-3
USN-8095-4
USN-8095-5
USN-8100-1
USN-8125-1
USN-8126-1
USN-8152-1
USN-8165-1
USN-8261-1

Affected Products

Ceph
Debian
Linuxmint
Linux Kernel
Ubuntu