CNNVD-202601-894 Information

CNNVD ID

CNNVD-202601-894

CVE-2025-68764

  • CNNVD Published: 2026-01-05

Description (Chinese)

Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于NFS自动挂载文件系统未继承ro、noexec、nodev、sync标志,可能导致权限配置不当。

Description (English)

Linux Kernel is the kernel used by Linux, the Open Source Operator System of the Linux Foundation of the United States. There is a security loophole in Linux Kernel, which stems from the non-inheritance of ro, noexec, nodev, sync symbols of the NFS auto-mounted file system, which may lead to an inappropriate allocation of privileges.

Hazard Level

Medium

Vulnerability Type

其他

Affected Vendor

Linux

Published

2026-01-05

Last Modified

2026-02-24

References

https://git.kernel.org/stable/c/4b296944e632cf4c6a4cc8e2585c6451eae47b1b https://git.kernel.org/stable/c/612cc98698d667df804792f0c47d4e501e66da29 https://git.kernel.org/stable/c/8675c69816e4276b979ff475ee5fac4688f80125 https://git.kernel.org/stable/c/df9b003a2ecacc7218486fbb31fe008c93097d5f https://access.redhat.com/security/cve/cve-2025-68764

Patch

https://www.kernel.org/

Share on: