« Volver al listado

CVE-2025-68784

Estado: AplazadaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

xfs: fix a UAF problem in xattr repair

The xchk_setup_xattr_buf function can allocate a new value buffer, which means that any reference to ab->value before the call could become a dangling pointer. Fix this by moving an assignment to after the buffer setup.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-68784",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "e47dcf113ae348678143cc935a1183059c02c9ad",
              "lessThan": "1e2d3aa19c7962b9474b22893160cb460494c45f",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "e47dcf113ae348678143cc935a1183059c02c9ad",
              "lessThan": "d29ed9ff972afe17c215cab171761d7a15d7063f",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "e47dcf113ae348678143cc935a1183059c02c9ad",
              "lessThan": "5990fd756943836978ad184aac980e2b36ab7e01",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "fs/xfs/scrub/attr_repair.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.10"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.10",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.12.64",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.3",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "6.19",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "fs/xfs/scrub/attr_repair.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-01-13T16:15:58.117",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/1e2d3aa19c7962b9474b22893160cb460494c45f",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/5990fd756943836978ad184aac980e2b36ab7e01",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/d29ed9ff972afe17c215cab171761d7a15d7063f",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Deferred",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nxfs: fix a UAF problem in xattr repair\n\nThe xchk_setup_xattr_buf function can allocate a new value buffer, which\nmeans that any reference to ab->value before the call could become a\ndangling pointer.  Fix this by moving an assignment to after the buffer\nsetup."
    },
    {
      "lang": "es",
      "value": "En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta:\n\nxfs: soluciona un problema de UAF en la reparación de xattr\n\nLa función xchk_setup_xattr_buf puede asignar un nuevo búfer de valor, lo que significa que cualquier referencia a ab->value antes de la llamada podría convertirse en un puntero colgante. Soluciona esto moviendo una asignación a después de la configuración del búfer."
    }
  ],
  "lastModified": "2026-06-17T09:59:35.023",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}