{"id":"DEBIAN-CVE-2025-68810","details":"In the Linux kernel, the following vulnerability has been resolved:  KVM: Disallow toggling KVM_MEM_GUEST_MEMFD on an existing memslot  Reject attempts to disable KVM_MEM_GUEST_MEMFD on a memslot that was initially created with a guest_memfd binding, as KVM doesn't support toggling KVM_MEM_GUEST_MEMFD on existing memslots.  KVM prevents enabling KVM_MEM_GUEST_MEMFD, but doesn't prevent clearing the flag.  Failure to reject the new memslot results in a use-after-free due to KVM not unbinding from the guest_memfd instance.  Unbinding on a FLAGS_ONLY change is easy enough, and can/will be done as a hardening measure (in anticipation of KVM supporting dirty logging on guest_memfd at some point), but fixing the use-after-free would only address the immediate symptom.    ==================================================================   BUG: KASAN: slab-use-after-free in kvm_gmem_release+0x362/0x400 [kvm]   Write of size 8 at addr ffff8881111ae908 by task repro/745    CPU: 7 UID: 1000 PID: 745 Comm: repro Not tainted 6.18.0-rc6-115d5de2eef3-next-kasan #3 NONE   Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 0.0.0 02/06/2015   Call Trace:    \u003cTASK\u003e    dump_stack_lvl+0x51/0x60    print_report+0xcb/0x5c0    kasan_report+0xb4/0xe0    kvm_gmem_release+0x362/0x400 [kvm]    __fput+0x2fa/0x9d0    task_work_run+0x12c/0x200    do_exit+0x6ae/0x2100    do_group_exit+0xa8/0x230    __x64_sys_exit_group+0x3a/0x50    x64_sys_call+0x737/0x740    do_syscall_64+0x5b/0x900    entry_SYSCALL_64_after_hwframe+0x4b/0x53   RIP: 0033:0x7f581f2eac31    \u003c/TASK\u003e    Allocated by task 745 on cpu 6 at 9.746971s:    kasan_save_stack+0x20/0x40    kasan_save_track+0x13/0x50    __kasan_kmalloc+0x77/0x90    kvm_set_memory_region.part.0+0x652/0x1110 [kvm]    kvm_vm_ioctl+0x14b0/0x3290 [kvm]    __x64_sys_ioctl+0x129/0x1a0    do_syscall_64+0x5b/0x900    entry_SYSCALL_64_after_hwframe+0x4b/0x53    Freed by task 745 on cpu 6 at 9.747467s:    kasan_save_stack+0x20/0x40    kasan_save_track+0x13/0x50    __kasan_save_free_info+0x37/0x50    __kasan_slab_free+0x3b/0x60    kfree+0xf5/0x440    kvm_set_memslot+0x3c2/0x1160 [kvm]    kvm_set_memory_region.part.0+0x86a/0x1110 [kvm]    kvm_vm_ioctl+0x14b0/0x3290 [kvm]    __x64_sys_ioctl+0x129/0x1a0    do_syscall_64+0x5b/0x900    entry_SYSCALL_64_after_hwframe+0x4b/0x53","modified":"2026-08-27T23:05:37.545927242Z","published":"2026-01-13T16:16:03.190Z","upstream":["CVE-2025-68810"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2025-68810"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.12.69-1"}]}],"versions":["6.12.38-1","6.12.41-1","6.12.43-1","6.12.43-1~bpo12+1","6.12.48-1","6.12.57-1","6.12.57-1~bpo12+1","6.12.63-1","6.12.63-1~bpo12+1","6.12.69-1~bpo12+1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2025-68810.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.18.3-1"}]}],"versions":["6.12.100-1","6.12.101-1","6.12.105-1","6.12.38-1","6.12.41-1","6.12.43-1","6.12.43-1~bpo12+1","6.12.48-1","6.12.57-1","6.12.57-1~bpo12+1","6.12.63-1","6.12.63-1~bpo12+1","6.12.69-1","6.12.69-1~bpo12+1","6.12.73-1","6.12.73-1~bpo12+1","6.12.74-1","6.12.74-2","6.12.74-2~bpo12+1","6.12.85-1","6.12.85-1~bpo12+1","6.12.86-1","6.12.86-1~bpo12+1","6.12.88-1","6.12.88-1~bpo12+1","6.12.90-1","6.12.90-1~bpo12+1","6.12.90-2","6.12.90-2~bpo12+1","6.12.94-1","6.12.94-1~bpo12+1","6.12.95-1","6.12.95-1~bpo12+1","6.12.96-1","6.13.10-1~exp1","6.13.11-1~exp1","6.13.2-1~exp1","6.13.3-1~exp1","6.13.4-1~exp1","6.13.5-1~exp1","6.13.6-1~exp1","6.13.7-1~exp1","6.13.8-1~exp1","6.13.9-1~exp1","6.13~rc6-1~exp1","6.13~rc7-1~exp1","6.14.3-1~exp1","6.14.5-1~exp1","6.14.6-1~exp1","6.15-1~exp1","6.15.1-1~exp1","6.15.2-1~exp1","6.15.3-1~exp1","6.15.4-1~exp1","6.15.5-1~exp1","6.15.6-1~exp1","6.15~rc7-1~exp1","6.16-1~exp1","6.16.1-1~exp1","6.16.10-1","6.16.11-1","6.16.12-1","6.16.12-1~bpo13+1","6.16.12-2","6.16.3-1","6.16.3-1~bpo13+1","6.16.5-1","6.16.6-1","6.16.7-1","6.16.8-1","6.16.9-1","6.16~rc7-1~exp1","6.17.10-1","6.17.11-1","6.17.12-1","6.17.13-1","6.17.13-1~bpo13+1","6.17.2-1~exp1","6.17.5-1~exp1","6.17.6-1","6.17.7-1","6.17.7-2","6.17.8-1","6.17.8-1~bpo13+1","6.17.9-1","6.18.1-1~exp1","6.18.2-1~exp1","6.18~rc4-1~exp1","6.18~rc4-1~exp2","6.18~rc5-1~exp1","6.18~rc6-1~exp1","6.18~rc7-1~exp1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2025-68810.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}