CVE-2025-68794
A critical flaw in the Linux kernel’s iomap subsystem can cause incorrect read operations, potentially leading to data corruption or loss. The bug occurs when the kernel miscalculates read ranges for non‑block‑aligned positions, causing it to skip too many bytes. The issue has been fixed in a recent kernel update.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Linux kernel, all users running affected kernel versions before the patch.
Real-world impact
An attacker could cause the system to read wrong data or corrupt files, leading to instability or data loss.
Why this severity
The CVSS score of 9.8 reflects that the flaw is exploitable over the network with no authentication, and it can compromise confidentiality, integrity, and availability of the system.
What to do about it
- 011. Update the Linux kernel to a version that includes the fix for CVE-2025-68794.
- 022. Reboot the system to load the new kernel.
NVD description indicates the vulnerability has been resolved.
Timeline
- Jan 13, 2026 · Jan 13, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 30, 2026 · 6d agoAdvisory updatedThe NVD record was last revised.
- Jul 30, 2026 · 6d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.