CVE-2025-68784

Source
https://cve.org/CVERecord?id=CVE-2025-68784
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-68784.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-68784
Downstream
Related
Published
2026-01-13T15:28:58.255Z
Modified
2026-03-20T12:46:28.887836Z
Summary
xfs: fix a UAF problem in xattr repair
Details

In the Linux kernel, the following vulnerability has been resolved:

xfs: fix a UAF problem in xattr repair

The xchksetupxattr_buf function can allocate a new value buffer, which means that any reference to ab->value before the call could become a dangling pointer. Fix this by moving an assignment to after the buffer setup.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/68xxx/CVE-2025-68784.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
e47dcf113ae348678143cc935a1183059c02c9ad
Fixed
1e2d3aa19c7962b9474b22893160cb460494c45f
Fixed
d29ed9ff972afe17c215cab171761d7a15d7063f
Fixed
5990fd756943836978ad184aac980e2b36ab7e01

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-68784.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.10.0
Fixed
6.12.64
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.3

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-68784.json"