CVE-2025-68243
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2025-68243 is a vulnerability in the Linux kernel's NFS (Network File System) client subsystem, specifically in the nfs_match_client() function. The flaw occurs when the TLS security policy is of type RPC_XPRTSEC_TLS_X509: the cert_serial and privkey_serial fields — which define the client's identity as presented to the server — are not checked during client matching, potentially allowing incorrect client identity association. It was published on December 16, 2025, and affects Linux kernel versions in the range 90c9550a8d65fb9b1bf87baf97a04ed91bf61b33 up to the patched commits. No CVSS score has been assigned by NVD at this time; the EPSS score is approximately 0.011% (CVE Record, Feedly).

Technical details

The root cause is an incomplete equality check in the nfs_match_client() function within the Linux kernel's NFS subsystem. When TLS mutual authentication via X.509 certificates (RPC_XPRTSEC_TLS_X509) is configured, the function fails to compare the cert_serial and privkey_serial fields, which uniquely identify the client certificate and private key pair used for the TLS session. This means two NFS clients with different X.509 identities could be incorrectly matched as the same client, potentially causing one client to reuse another's established connection. No CWE classification has been formally assigned by NVD. The fix is available in kernel commits b8fa37219074811c04d4ecb742c73e2b296da6a8 and fb2cba0854a7f315c8100a807a6959b99d72479e (kernel.org patch 1, kernel.org patch 2).

Impact

Exploitation of this vulnerability could result in incorrect client identity resolution when multiple NFS clients with different X.509 TLS certificates connect to the same server. This may allow one client to inadvertently reuse another client's NFS connection, potentially leading to unauthorized access to file system resources, data exposure, or integrity violations in environments relying on per-client TLS certificate-based authentication. The impact is primarily relevant to multi-tenant or security-sensitive NFS deployments using RPC_XPRTSEC_TLS_X509 (CVE Record).

Mitigation and workarounds

The vulnerability is resolved in Linux kernel versions 6.17.9 and 6.18, as well as in the stable branch commits b8fa37219074811c04d4ecb742c73e2b296da6a8 and fb2cba0854a7f315c8100a807a6959b99d72479e. Administrators should update to a patched kernel version as soon as it is available for their distribution. As a workaround, environments not using RPC_XPRTSEC_TLS_X509 for NFS are not affected and require no immediate action (kernel.org patch 1, kernel.org patch 2).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-64557NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-selftests-internal
NoNoJul 29, 2026
CVE-2026-64556NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-64k-devel
NoNoJul 29, 2026
CVE-2026-64555NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-azure-fde-6.14
NoNoJul 27, 2026
CVE-2026-64554NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-gcp-6.14
NoYesJul 27, 2026
CVE-2026-64553NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-64k-debug-modules-internal
NoYesJul 27, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management