CVE-2025-68349

Source
https://cve.org/CVERecord?id=CVE-2025-68349
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-68349.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-68349
Downstream
Related
Published
2025-12-24T10:32:41.253Z
Modified
2026-03-20T12:46:22.905955Z
Summary
NFSv4/pNFS: Clear NFS_INO_LAYOUTCOMMIT in pnfs_mark_layout_stateid_invalid
Details

In the Linux kernel, the following vulnerability has been resolved:

NFSv4/pNFS: Clear NFSINOLAYOUTCOMMIT in pnfsmarklayoutstateidinvalid

Fixes a crash when layout is null during this call stack:

writeinode -> nfs4writeinode -> pnfslayoutcommit_inode

pnfssetlayoutcommit relies on the lseg refcount to keep the layout around. Need to clear NFSINOLAYOUTCOMMIT otherwise we might attempt to reference a null layout.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/68xxx/CVE-2025-68349.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
fe1cf9469d7bcb6af27e42eb555a41b0135bce4a
Fixed
084bebe82ad86f718a3af84f34761863e63164ed
Fixed
b6e4e3a08c03200cc4b8067ec8ab3172a989d6fc
Fixed
104080582ae0aa6dce6c6d75ff89062efe84673b
Fixed
f718f9ea6094843b8c059b073af49ad61e9f49bb
Fixed
59947dff0fb7c19c09ce6dccbcd253fd542b6c25
Fixed
ca2e7fdad7c683b64821c94a58b9b68733214dad
Fixed
38694f9aae00459ab443a7dc8b3949a6b33b560a
Fixed
e0f8058f2cb56de0b7572f51cd563ca5debce746

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-68349.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.10.0
Fixed
5.10.248
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.198
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.160
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.120
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.63
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.17.13
Type
ECOSYSTEM
Events
Introduced
6.18.0
Fixed
6.18.2

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-68349.json"