CVE-2025-68361

Updated on 24 Dec 2025

Severity

7.0 High severity

Details

CVSS score
7.0

Overview

About vulnerability

In the Linux kernel, the following vulnerability has been resolved: erofs: limit the level of fs stacking for file-backed mounts Otherwise, it could cause potential kernel stack overflow (e.g., EROFS mounting itself). A vulnerability was discovered in the Linux kernel’s EROFS (Enhanced Read-Only File System) implementation related to file-backed mount stacking. Without limiting the depth of filesystem stacking, it is possible for an attacker to mount EROFS recursively (e.g., EROFS mounting itself) in such a way that kernel stack usage grows uncontrollably, potentially leading to a kernel stack overflow and system crash. Exploitation requires local access and the ability to initiate nested file-backed erofs mounts.

Details

KernelCare state

Live-patch status from KernelCare for each operating system.

Operating system Status Covered kernels
Debian 13 Will Not Fix