CVE-2025-68315

CRITICALCVSS 9.8/10EPSS 0.16%

Last modified

CVE-2025-68315 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to detect potential corrupted nid in free_nid_list As reported, on-disk footer.ino and footer.nid is the same and out-of-range, let's add sanity check on f2fs_alloc_nid() to detect any potential corruption in free_nid_list.. EPSS estimates a 0.16% chance of exploitation in the next 30 days.

Description

In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to detect potential corrupted nid in free_nid_list As reported, on-disk footer.ino and footer.nid is the same and out-of-range, let's add sanity check on f2fs_alloc_nid() to detect any potential corruption in free_nid_list.

Metrics

CVSS 3.1
9.8/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
0.16%

5.9th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
LinuxLinux>= 98e4da8ca301e062d79ae168c67e56f3c3de3ce4, < 88b2ddb0c4f1dc874d4598e78cc830c64315ed86; >= 98e4da8ca301e062d79ae168c67e56f3c3de3ce4, < 9337ed5e777e1c19854928cba7a8131dd00e611b; >= 98e4da8ca301e062d79ae168c67e56f3c3de3ce4, < 6b9525596a83cd5b7bbc2c7bd5f9ad9cf5ad60fa; >= 98e4da8ca301e062d79ae168c67e56f3c3de3ce4, < adbcb34f03abb89e681a5907c4c3ce4bf224991d; >= 98e4da8ca301e062d79ae168c67e56f3c3de3ce4, < 8fc6056dcf79937c46c97fa4996cda65956437a9
LinuxLinux3.8

References

Timeline

Published
Last Modified
Status
Deferred

Frequently Asked Questions

What is CVE-2025-68315?
In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to detect potential corrupted nid in free_nid_list As reported, on-disk footer.ino and footer.nid is the same and out-of-range, let's add sanity check on f2fs_alloc_nid() to detect any potential corruption in free_nid_list.
How severe is CVE-2025-68315?
CVE-2025-68315 has a CVSS score of 9.8/10 (CRITICAL severity). The EPSS model estimates a 0.16% probability of exploitation in the next 30 days.
How do I fix CVE-2025-68315?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2025

Are you affected by CVE-2025-68315?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST