CVE-2025-68784 addresses a Use-After-Free (UAF) vulnerability within the XFS filesystem's extended attribute (xattr) repair function in the Linux kernel. Specifically, the xchk_setup_xattr_buf function could invalidate existing pointers to an attribute's value buffer, leading to a dangling pointer. While no CVSS score is available, its FAUCET Risk Score of 7/100 suggests a low to moderate potential impact, likely requiring local access or specific conditions to trigger. There is currently no public exploit code available, nor is it listed on the KEV catalog, indicating no active exploitation. Community discussion and media coverage are minimal, with only one article from openSUSE mentioning a security update.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Linux | Linux | 6.10CNA affecteddefault affected | |
| Linux | Linux | >= e47dcf113ae348678143cc935a1183059c02c9ad, < 1e2d3aa19c7962b9474b22893160cb460494c45f, >= e47dcf113ae348678143cc935a1183059c02c9ad, < 5990fd756943836978ad184aac980e2b36ab7e01, >= e47dcf113ae348678143cc935a1183059c02c9ad, < d29ed9ff972afe17c215cab171761d7a15d7063fCNA affecteddefault unaffected |
CVSS data has not been published for this CVE.
Linux kernel (Raspberry Pi) vulnerabilities
May 7, 2026Linux kernel vulnerabilities
May 7, 2026Linux kernel vulnerabilities
Apr 23, 2026Linux kernel (GCP) vulnerabilities
Apr 17, 2026Linux kernel vulnerabilities
Apr 16, 2026kernel: xfs: fix a UAF problem in xattr repair
Jan 13, 2026