{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2025-68349","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2025-12-16T14:48:05.300Z","datePublished":"2025-12-24T10:32:41.253Z","dateUpdated":"2026-09-08T08:43:14.323Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-05T12:10:59.666Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nNFSv4/pNFS: Clear NFS_INO_LAYOUTCOMMIT in pnfs_mark_layout_stateid_invalid\n\nFixes a crash when layout is null during this call stack:\n\nwrite_inode\n    -> nfs4_write_inode\n        -> pnfs_layoutcommit_inode\n\npnfs_set_layoutcommit relies on the lseg refcount to keep the layout\naround. Need to clear NFS_INO_LAYOUTCOMMIT otherwise we might attempt\nto reference a null layout."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:N - The NFSv4.1+ pNFS client state is driven by network replies from its metadata and data servers; a malicious or compromised pNFS server can return layout-state errors that lead to the client crash.\nAC:L - The server controls layout ranges, data-server replies, and stateid-error timing, allowing it to establish a pending layoutcommit and then invalidate the last layout segment without relying on an uncontrollable race.\nPR:N - The attacker needs no account or capability on the client; CAP_SYS_ADMIN is required only for the victim's initial NFS mount, and ordinary deployments may use unauthenticated AUTH_SYS server communication.\nUI:N - In a pre-mounted pNFS or NFS-root deployment, automated writes and kernel writeback can complete the trigger sequence without human action at exploitation time.\nS:U - The resulting failure affects the NFS client kernel within its existing security authority and does not cross a virtualization, sandbox, or IOMMU boundary.\nC:N - The stale flag causes a direct NULL dereference of the absent layout rather than an out-of-bounds read, use-after-free access, or information-disclosure primitive.\nI:N - The defect does not provide an attacker-controlled write or corrupt adjacent memory; execution faults while attempting to traverse the layout segment list through a NULL layout pointer.\nA:H - The NULL dereference occurs in kernel writeback and can produce an oops or panic, taking the client system or critical kernel functionality out of service."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/nfs/pnfs.c"],"versions":[{"version":"fe1cf9469d7bcb6af27e42eb555a41b0135bce4a","lessThan":"084bebe82ad86f718a3af84f34761863e63164ed","status":"affected","versionType":"git"},{"version":"fe1cf9469d7bcb6af27e42eb555a41b0135bce4a","lessThan":"b6e4e3a08c03200cc4b8067ec8ab3172a989d6fc","status":"affected","versionType":"git"},{"version":"fe1cf9469d7bcb6af27e42eb555a41b0135bce4a","lessThan":"104080582ae0aa6dce6c6d75ff89062efe84673b","status":"affected","versionType":"git"},{"version":"fe1cf9469d7bcb6af27e42eb555a41b0135bce4a","lessThan":"f718f9ea6094843b8c059b073af49ad61e9f49bb","status":"affected","versionType":"git"},{"version":"fe1cf9469d7bcb6af27e42eb555a41b0135bce4a","lessThan":"59947dff0fb7c19c09ce6dccbcd253fd542b6c25","status":"affected","versionType":"git"},{"version":"fe1cf9469d7bcb6af27e42eb555a41b0135bce4a","lessThan":"ca2e7fdad7c683b64821c94a58b9b68733214dad","status":"affected","versionType":"git"},{"version":"fe1cf9469d7bcb6af27e42eb555a41b0135bce4a","lessThan":"38694f9aae00459ab443a7dc8b3949a6b33b560a","status":"affected","versionType":"git"},{"version":"fe1cf9469d7bcb6af27e42eb555a41b0135bce4a","lessThan":"e0f8058f2cb56de0b7572f51cd563ca5debce746","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/nfs/pnfs.c"],"versions":[{"version":"4.10","status":"affected"},{"version":"0","lessThan":"4.10","status":"unaffected","versionType":"semver"},{"version":"5.10.248","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.198","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.160","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.120","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.63","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.17.13","lessThanOrEqual":"6.17.*","status":"unaffected","versionType":"semver"},{"version":"6.18.2","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"6.19","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.10","versionEndExcluding":"5.10.248"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.10","versionEndExcluding":"5.15.198"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.10","versionEndExcluding":"6.1.160"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.10","versionEndExcluding":"6.6.120"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.10","versionEndExcluding":"6.12.63"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.10","versionEndExcluding":"6.17.13"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.10","versionEndExcluding":"6.18.2"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.10","versionEndExcluding":"6.19"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/084bebe82ad86f718a3af84f34761863e63164ed"},{"url":"https://git.kernel.org/stable/c/b6e4e3a08c03200cc4b8067ec8ab3172a989d6fc"},{"url":"https://git.kernel.org/stable/c/104080582ae0aa6dce6c6d75ff89062efe84673b"},{"url":"https://git.kernel.org/stable/c/f718f9ea6094843b8c059b073af49ad61e9f49bb"},{"url":"https://git.kernel.org/stable/c/59947dff0fb7c19c09ce6dccbcd253fd542b6c25"},{"url":"https://git.kernel.org/stable/c/ca2e7fdad7c683b64821c94a58b9b68733214dad"},{"url":"https://git.kernel.org/stable/c/38694f9aae00459ab443a7dc8b3949a6b33b560a"},{"url":"https://git.kernel.org/stable/c/e0f8058f2cb56de0b7572f51cd563ca5debce746"}],"title":"NFSv4/pNFS: Clear NFS_INO_LAYOUTCOMMIT in pnfs_mark_layout_stateid_invalid","x_generator":{"engine":"bippy-1.2.0"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-06-16T19:27:27.700810Z","id":"CVE-2025-68349","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-06-16T19:27:54.246Z"}},{"x_adpType":"supplier","providerMetadata":{"orgId":"0b142b55-0307-4c5a-b3c9-f314f3fb7c5e","shortName":"siemens-SADP","dateUpdated":"2026-09-08T08:43:14.323Z"},"affected":[{"vendor":"Siemens","product":"SIMATIC S7-1500 CPU 1518-4 PN/DP MFP","versions":[{"status":"affected","version":"V3.1.6","lessThan":"*","versionType":"custom"}],"defaultStatus":"unknown"},{"vendor":"Siemens","product":"SIMATIC S7-1500 CPU 1518-4 PN/DP MFP","versions":[{"status":"affected","version":"V3.1.6","lessThan":"*","versionType":"custom"}],"defaultStatus":"unknown"},{"vendor":"Siemens","product":"SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP","versions":[{"status":"affected","version":"V3.1.6","lessThan":"*","versionType":"custom"}],"defaultStatus":"unknown"},{"vendor":"Siemens","product":"SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP","versions":[{"status":"affected","version":"V3.1.6","lessThan":"*","versionType":"custom"}],"defaultStatus":"unknown"},{"vendor":"Siemens","product":"SIPLUS S7-1500 CPU 1518-4 PN/DP MFP","versions":[{"status":"affected","version":"V3.1.6","lessThan":"*","versionType":"custom"}],"defaultStatus":"unknown"}],"references":[{"url":"https://cert-portal.siemens.com/productcert/html/ssa-019113.html"}]}]}}