# CVE-2025-68764

## Summary

- **CVE ID:** CVE-2025-68764
- **Severity:** HIGH
- **CVSS Score:** 7.8 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
- **CWE:** N/A
- **Published:** Jan 5, 2026
- **Last Modified:** Sep 8, 2026

## Description

In the Linux kernel, the following vulnerability has been resolved:

NFS: Automounted filesystems should inherit ro,noexec,nodev,sync flags

When a filesystem is being automounted, it needs to preserve the
user-set superblock mount options, such as the "ro" flag.

## Affected Products

- Linux — Linux (f2aedb713c284429987dc66c7aaf38decfc8da2a)
- Linux — Linux (5.6)
- Linux — Linux (0)
- Linux — Linux (5.10.248)
- Linux — Linux (5.15.198)
- Linux — Linux (6.1.160)
- Linux — Linux (6.6.120)
- Linux — Linux (6.12.63)
- Linux — Linux (6.17.13)
- Linux — Linux (6.18.2)
- Linux — Linux (6.19)

## References

- [CNA](https://git.kernel.org/stable/c/a3dc6c40bcab1a888d5c0d134ccc0746b4c98929)
- [CNA](https://git.kernel.org/stable/c/ba1495aefd22fcf0746a2a3025c95d766d7cde4d)
- [CNA](https://git.kernel.org/stable/c/c09070b4def1b34e473a746c6a5331ccb80902c1)
- [CNA](https://git.kernel.org/stable/c/dce10c59211e5cd763a62ea01e79b82a629811e3)
- [CNA](https://git.kernel.org/stable/c/612cc98698d667df804792f0c47d4e501e66da29)
- [CNA](https://git.kernel.org/stable/c/4b296944e632cf4c6a4cc8e2585c6451eae47b1b)
- [CNA](https://git.kernel.org/stable/c/df9b003a2ecacc7218486fbb31fe008c93097d5f)
- [CNA](https://git.kernel.org/stable/c/8675c69816e4276b979ff475ee5fac4688f80125)
- [siemens-SADP](https://cert-portal.siemens.com/productcert/html/ssa-019113.html)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.15%
- **EPSS Percentile:** 4.4

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-18._