CVE-2025-68239
Description
In the Linux kernel, the following vulnerability has been resolved: binfmt_misc: restore write access before closing files opened by open_exec() bm_register_write() opens an executable file using open_exec(), which internally calls do_open_execat() and denies write access on the file to avoid modification while it is being executed. However, when an error occurs, bm_register_write() closes the file using filp_close() directly. This does not restore the write permission, which may cause subsequent write operations on the same file to fail. Fix this by calling exe_file_allow_write_access() before filp_close() to restore the write permission properly.
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ if you've already worked around this in production โ publish your fix to the community-verified tier.
โ Propose a mitigation on Community โ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| sles | affected | | |
| debian | bookworm | fixed | 6.1.170-1 |
| debian | forky | fixed | 6.17.9-1 |
| debian | sid | fixed | 6.17.9-1 |
| debian | trixie | fixed | 6.12.85-1 |
| debian | bullseye | fixed | 6.1.170-1~deb11u1 |
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| gcp | | |
References
- https://www.suse.com/security/cve/CVE-2025-68239.html
- https://security-tracker.debian.org/tracker/CVE-2025-68239
- https://git.kernel.org/stable/c/480ac88431703f2adbb8e6b5bd73c3f3cf9f3d7f
- https://git.kernel.org/stable/c/54274ff90488b6c0f595a6518faed3cf0bc966eb
- https://git.kernel.org/stable/c/6cce7bc7fac8471c832696720d9c8f2a976d9c54
- https://git.kernel.org/stable/c/90f601b497d76f40fa66795c3ecf625b6aced9fd
- https://git.kernel.org/stable/c/e785f552ab04dbca01d31f0334f4561240b04459
- https://git.kernel.org/stable/c/fbab8c08e1a6dbaef81e22d672a7647553101d16
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.