PT-2026-2553 · Linux+2 · Linux Kernel+2

CVE-2025-68821

·

Published

2026-01-11

·

Updated

2026-08-30

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The Linux kernel contains a flaw related to the FUSE (Filesystem in Userspace) implementation. A deadlock situation can occur when readahead requests interact with inode eviction and reclaim processes. Specifically, if a FUSE server does not implement the 'open' operation, the system may skip allocating resources needed for release operations. This can lead to a deadlock when reclaim attempts to evict an inode while inflight readahead requests are active, as the reclaim process can block indefinitely waiting for a lock held by the readahead request. The issue arises because the inode reference is not properly managed during readahead, potentially allowing the inode to be evicted while readahead operations are still in progress. The commit e26ee4efbc79 aimed to address a related issue but inadvertently introduced this deadlock scenario.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-11495
CVE-2025-68821
ECHO-2AEC-68FE-2A65
MGASA-2026-0017
MGASA-2026-0018
OESA-2026-1303
OESA-2026-1304
OESA-2026-1305
OPENSUSE-SU-2026:20287-1
SUSE-SU-2026:20555-1
SUSE-SU-2026:20570-1
SUSE-SU-2026:20599-1
SUSE-SU-2026:20615-1
USN-8096-1
USN-8096-2
USN-8096-3
USN-8096-4
USN-8096-5
USN-8116-1
USN-8177-1
USN-8177-2
USN-8179-1
USN-8179-2
USN-8179-3
USN-8179-4
USN-8183-1
USN-8183-2
USN-8184-1
USN-8185-1
USN-8185-2
USN-8203-1
USN-8204-1
USN-8245-1
USN-8257-1
USN-8258-1
USN-8260-1
USN-8265-1
USN-8440-1

Affected Products

Linuxmint
Linux Kernel
Ubuntu