PT-2026-2541 · Linux+2 · Linux Kernel+2

CVE-2025-68809

·

Published

2026-01-13

·

Updated

2026-08-30

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The Linux kernel’s ksmbd component has an issue related to inconsistent locking when accessing the m flags field within the vfs cache. Specifically, some code paths read and modify m flags under ci->m lock, while others do not, creating a data race. This can lead to a loss or inconsistent state of delete-on-close and pending-delete bits, resulting in unexpected file deletion behavior, such as files remaining on disk after a delete-on-close operation or disappearing while still in use. The issue affects functions like ksmbd query inode status(), ksmbd inode close(), ksmbd inode pending delete(), ksmbd set inode pending delete(), ksmbd clear inode pending delete(), and ksmbd fd set delete on close().
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-74423
CVE-2025-68809
ECHO-1C34-4B95-CA39
MGASA-2026-0017
MGASA-2026-0018
USN-8177-1
USN-8177-2
USN-8179-1
USN-8179-2
USN-8179-3
USN-8179-4
USN-8183-1
USN-8183-2
USN-8184-1
USN-8185-1
USN-8185-2
USN-8203-1
USN-8204-1
USN-8245-1
USN-8257-1
USN-8258-1
USN-8260-1
USN-8261-1
USN-8265-1
USN-8440-1

Affected Products

Linuxmint
Linux Kernel
Ubuntu