# CVE-2025-68820

## Summary

- **CVE ID:** CVE-2025-68820
- **Severity:** UNKNOWN
- **CVSS Score:** 1.51
- **CWE:** N/A
- **Published:** Jan 13, 2026
- **Last Modified:** Sep 17, 2026

## Description

In the Linux kernel, the following vulnerability has been resolved:

ext4: xattr: fix null pointer deref in ext4_raw_inode()

If ext4_get_inode_loc() fails (e.g. if it returns -EFSCORRUPTED),
iloc.bh will remain set to NULL. Since ext4_xattr_inode_dec_ref_all()
lacks error checking, this will lead to a null pointer dereference
in ext4_raw_inode(), called right after ext4_get_inode_loc().

Found by Linux Verification Center (linuxtesting.org) with SVACE.

## Affected Products

- Linux — Linux (76c365fa7e2a8bb85f0190cdb4b8cdc99b2fdce3)
- Linux — Linux (f737418b6de31c962c7192777ee4018906975383)
- Linux — Linux (cf9291a3449b04688b81e32621e88de8f4314b54)
- Linux — Linux (362a90cecd36e8a5c415966d0b75b04a0270e4dd)
- Linux — Linux (eb59cc31b6ea076021d14b04e7faab1636b87d0e)
- Linux — Linux (c8e008b60492cf6fd31ef127aea6d02fd3d314cd)
- Linux — Linux (6aff941cb0f7d0c897c3698ad2e30672709135e3)
- Linux — Linux (3bc6317033f365ce578eb6039445fb66162722fd)
- Linux — Linux (836e625b03a666cf93ff5be328c8cb30336db872)
- Linux — Linux (6.15)
- Linux — Linux (0)
- Linux — Linux (5.10.248)
- Linux — Linux (5.15.198)
- Linux — Linux (6.1.160)
- Linux — Linux (6.6.120)
- Linux — Linux (6.12.64)
- Linux — Linux (6.18.3)
- Linux — Linux (6.19)
- Linux — Linux (5.10.237)
- Linux — Linux (5.15.181)
- Linux — Linux (6.1.135)
- Linux — Linux (6.6.88)
- Linux — Linux (6.12.24)
- Linux — Linux (5.4.293)
- Linux — Linux (6.13.12)
- Linux — Linux (6.14.3)

## References

- [CNA](https://git.kernel.org/stable/c/b72a3476f0c97d02f63a6e9fff127348d55436f6)
- [CNA](https://git.kernel.org/stable/c/3d8d22e75f7edfa0b30ff27330fd6a1285d594c3)
- [CNA](https://git.kernel.org/stable/c/190ad0f22ba49f1101182b80e3af50ca2ddfe72f)
- [CNA](https://git.kernel.org/stable/c/b5d942922182e82724b7152cb998f540132885ec)
- [CNA](https://git.kernel.org/stable/c/5b154e901fda2e98570b8f426a481f5740097dc2)
- [CNA](https://git.kernel.org/stable/c/ce5f54c065a4a7cbb92787f4f140917112350142)
- [CNA](https://git.kernel.org/stable/c/b97cb7d6a051aa6ebd57906df0e26e9e36c26d14)
- [siemens-SADP](https://cert-portal.siemens.com/productcert/html/ssa-019113.html)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.21%
- **EPSS Percentile:** 11.0

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-17._