CVE-2025-68210
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2025-68210 is a denial-of-service vulnerability in the Linux kernel's EROFS (Enhanced Read-Only File System) subsystem caused by an infinite loop triggered by incomplete or truncated zstd-compressed data in crafted (deliberately corrupted) images. The decompression logic fails to handle truncated compressed data correctly, causing the kernel to spin indefinitely. It was published on December 16, 2025, and affects Linux kernel versions from commit 7c35de4df105 up to the patched commits in stable branches. The estimated CVSS severity is Medium, with an EPSS score of 0.000170 (Feedly, EUVD).

Technical details

The root cause is improper handling of incomplete or truncated compressed data within the EROFS zstd decompression path (CWE-835: Loop with Unreachable Exit Condition). When a crafted EROFS image contains zstd-compressed data that is deliberately truncated, the kernel decompression routine enters an infinite loop because it does not correctly detect or handle the incomplete data condition and exit. Exploitation requires the ability to mount or present a crafted EROFS image to the kernel — for example, via a malicious disk image or filesystem. Patches were applied to stable kernel branches via commits 4d0e0bb1908a, 1f86d73a0afe, and f2a12cc3b97f (Feedly, EUVD).

Impact

Successful exploitation causes the affected Linux kernel to enter an infinite loop during EROFS zstd decompression, resulting in a complete denial of service (system hang or CPU starvation) on the affected host. Availability is the primary impact, with no direct confidentiality or integrity compromise reported. Systems that mount untrusted EROFS images — such as container runtimes, embedded systems, or storage appliances using EROFS — are most at risk (Feedly, EUVD).

Mitigation and workarounds

The Linux kernel maintainers have released patches addressing this vulnerability in the following stable branches: Linux 6.12.59, Linux 6.17.9, and Linux 6.18. The relevant patch commits are 4d0e0bb1908acac5b27d30b45c450e8ead97eb00, 1f86d73a0afe43b6a85d2aa8207853350b7e2111, and f2a12cc3b97f062186568a7b94ddb7aa2ef68140. Administrators should update to a patched kernel version as soon as possible. As a workaround, avoid mounting untrusted or externally supplied EROFS images on unpatched systems, and restrict access to filesystem mounting capabilities where feasible (EUVD, Feedly).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-64557NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-selftests-internal
NoNoJul 29, 2026
CVE-2026-64556NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-64k-devel
NoNoJul 29, 2026
CVE-2026-64555NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-azure-fde-6.14
NoNoJul 27, 2026
CVE-2026-64554NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-gcp-6.14
NoYesJul 27, 2026
CVE-2026-64553NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-64k-debug-modules-internal
NoYesJul 27, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management