
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-68210 is a denial-of-service vulnerability in the Linux kernel's EROFS (Enhanced Read-Only File System) subsystem caused by an infinite loop triggered by incomplete or truncated zstd-compressed data in crafted (deliberately corrupted) images. The decompression logic fails to handle truncated compressed data correctly, causing the kernel to spin indefinitely. It was published on December 16, 2025, and affects Linux kernel versions from commit 7c35de4df105 up to the patched commits in stable branches. The estimated CVSS severity is Medium, with an EPSS score of 0.000170 (Feedly, EUVD).
The root cause is improper handling of incomplete or truncated compressed data within the EROFS zstd decompression path (CWE-835: Loop with Unreachable Exit Condition). When a crafted EROFS image contains zstd-compressed data that is deliberately truncated, the kernel decompression routine enters an infinite loop because it does not correctly detect or handle the incomplete data condition and exit. Exploitation requires the ability to mount or present a crafted EROFS image to the kernel — for example, via a malicious disk image or filesystem. Patches were applied to stable kernel branches via commits 4d0e0bb1908a, 1f86d73a0afe, and f2a12cc3b97f (Feedly, EUVD).
Successful exploitation causes the affected Linux kernel to enter an infinite loop during EROFS zstd decompression, resulting in a complete denial of service (system hang or CPU starvation) on the affected host. Availability is the primary impact, with no direct confidentiality or integrity compromise reported. Systems that mount untrusted EROFS images — such as container runtimes, embedded systems, or storage appliances using EROFS — are most at risk (Feedly, EUVD).
The Linux kernel maintainers have released patches addressing this vulnerability in the following stable branches: Linux 6.12.59, Linux 6.17.9, and Linux 6.18. The relevant patch commits are 4d0e0bb1908acac5b27d30b45c450e8ead97eb00, 1f86d73a0afe43b6a85d2aa8207853350b7e2111, and f2a12cc3b97f062186568a7b94ddb7aa2ef68140. Administrators should update to a patched kernel version as soon as possible. As a workaround, avoid mounting untrusted or externally supplied EROFS images on unpatched systems, and restrict access to filesystem mounting capabilities where feasible (EUVD, Feedly).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."