CVE-2025-68349High· 7.5▾ TwilightIn the Linux kernel, the following vulnerability has been resolved: NFSv4/pNFS: Clear NFS_INO_LAYOUTCOMMIT in pnfs_mark_layout_stateid_invalid Fixes a crash when layout is null during this call stack: write_inode -> nfs4_write_ino…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake. The CVSS score shown above comes from the assigning CNA record, not NVD.
Exploit-prediction probability, daily snapshots since Sep 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CVEORG
Last analysed / modified upstream
0.7%
0.7% → 0.7%
In the Linux kernel, the following vulnerability has been resolved:
NFSv4/pNFS: Clear NFS_INO_LAYOUTCOMMIT in pnfs_mark_layout_stateid_invalid
Fixes a crash when layout is null during this call stack:
write_inode -> nfs4_write_inode -> pnfs_layoutcommit_inode
pnfs_set_layoutcommit relies on the lseg refcount to keep the layout around. Need to clear NFS_INO_LAYOUTCOMMIT otherwise we might attempt to reference a null layout.
Linux >= fe1cf9469d7bcb6af27e42eb555a41b0135bce4a < 084bebe82ad86f718a3af84f34761863e63164edLinux >= fe1cf9469d7bcb6af27e42eb555a41b0135bce4a < b6e4e3a08c03200cc4b8067ec8ab3172a989d6fcLinux >= fe1cf9469d7bcb6af27e42eb555a41b0135bce4a < 104080582ae0aa6dce6c6d75ff89062efe84673bLinux >= fe1cf9469d7bcb6af27e42eb555a41b0135bce4a < f718f9ea6094843b8c059b073af49ad61e9f49bbLinux >= fe1cf9469d7bcb6af27e42eb555a41b0135bce4a < 59947dff0fb7c19c09ce6dccbcd253fd542b6c25Linux >= fe1cf9469d7bcb6af27e42eb555a41b0135bce4a < ca2e7fdad7c683b64821c94a58b9b68733214dadLinux >= fe1cf9469d7bcb6af27e42eb555a41b0135bce4a < 38694f9aae00459ab443a7dc8b3949a6b33b560aLinux >= fe1cf9469d7bcb6af27e42eb555a41b0135bce4a < e0f8058f2cb56de0b7572f51cd563ca5debce746Linux 4.10Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-93205Noneiommu/arm-smmu-v3: Manage teardown with devm
CVE-2026-93207NoneSUNRPC: Zero rpc_gss_wire_cred at svcauth_gss_decode_credbody() entry
CVE-2026-93206NonePCI/proc: Use file_ns_capable() when checking config space read access
CVE-2026-93213Noneof: fix out-of-bounds read in of_alias_scan() stem parser
CVE-2026-93209NoneBluetooth: hci_core: use skb_get() instead of skb_clone() for req_skb
CVE-2026-93208Nonekasan: fix cache shrink race with CPU hotplug