VDB

DEBIAN-CVE-2025-68820

DEBIAN-CVE-2025-68820 PUBLISHED

In the Linux kernel, the following vulnerability has been resolved: ext4: xattr: fix null pointer deref in ext4_raw_inode() If ext4_get_inode_loc() fails (e.g. if it returns -EFSCORRUPTED), iloc.bh will remain set to NULL. Since ext4_xattr_inode_dec_ref_all() lacks error checking, this will lead to a null pointer dereference in ext4_raw_inode(), called right after ext4_get_inode_loc(). Found by Linux Verification Center (linuxtesting.org) with SVACE.

Affected Products

VendorProductVersions
Debian:11linux-6.1*, *, 6.1.159-1
Debian:11linux5.10.244-1, 5.10.234-1, 5.10.209-1
Debian:14linux6.17.12-1, 6.17.13-1, 6.17.13-1
Debian:13linux*, 6.12.69-1, 6.12.63-1
Debian:12linux6.1.55-1, 6.1.106-3, 6.1.147-1

Exploit Intelligence

Timeline

  • Jan 13, 2026 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›