Skip to main content

Boteraser | Website and Server Security Solutions

🛡️ CVE-2025-68740 — kernel

⚪ Unknown ✅ No Known Exploit NVD
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

ima: Handle error code returned by ima_filter_rule_match()

In the Linux kernel, the following vulnerability has been resolved:

ima: Handle error code returned by ima_filter_rule_match()

In ima_match_rules(), if ima_filter_rule_match() returns -ENOENT due to

the rule being NULL, the function incorrectly skips the 'if (!rc)' check

and sets 'result = true'. The LSM rule is considered a match, causing

extra files to be measured by IMA.

This issue can be reproduced in the following scenario:

After unloading the SELinux policy module via 'semodule -d', if an IMA

measurement is triggered before ima_lsm_rules is updated,

in ima_match_rules(), the first call to ima_filter_rule_match() returns

-ESTALE. This causes the code to enter the 'if (rc == -ESTALE &&

!rule_reinitialized)' block, perform ima_lsm_copy_rule() and retry. In

ima_lsm_copy_rule(), since the SELinux module has been removed, the rule

becomes NULL, and the second call to ima_filter_rule_match() returns

-ENOENT. This bypasses the 'if (!rc)' check and results in a false match.

Call trace:

selinux_audit_rule_match+0x310/0x3b8

security_audit_rule_match+0x60/0xa0

ima_match_rules+0x2e4/0x4a0

ima_match_policy+0x9c/0x1e8

ima_get_action+0x48/0x60

process_measurement+0xf8/0xa98

ima_bprm_check+0x98/0xd8

security_bprm_check+0x5c/0x78

search_binary_handler+0x6c/0x318

exec_binprm+0x58/0x1b8

bprm_execve+0xb8/0x130

do_execveat_common.isra.0+0x1a8/0x258

__arm64_sys_execve+0x48/0x68

invoke_syscall+0x50/0x128

el0_svc_common.constprop.0+0xc8/0xf0

do_el0_svc+0x24/0x38

el0_svc+0x44/0x200

el0t_64_sync_handler+0x100/0x130

el0t_64_sync+0x3c8/0x3d0

Fix this by changing 'if (!rc)' to 'if (rc <= 0)' to ensure that error

codes like -ENOENT do not bypass the check and accidentally result in a

successful match.

Affected software

CVE-2025-68740 is recorded against 2 packages.

  • kernel (from 6.18.0 up to 6.18.2)
  • unknown

Timeline and source

Published on 24 December 2025 and last revised on 12 August 2026. No public exploit is currently recorded for this entry. Record sourced from NVD.

References

git.kernel.org (Web)
git.kernel.org (Web)
git.kernel.org (Web)
git.kernel.org (Web)
git.kernel.org (Web)
git.kernel.org (Web)
git.kernel.org (Web)
git.kernel.org (Web)
github.com (Advisory)
nvd.nist.gov (Advisory)
git.kernel.org (Package)

CVE-2025-68740 on other distributions

Each distribution ships its own build and its own fixed version. Pick the one you run:

Details

Severity Unknown
CVSS Score N/A
CVSS Vector N/A
CWE N/A
Public Exploit ✅ No
Source NVD
Published 2025-12-24
Updated 2026-08-20
Modified 2026-08-12
Fix URL N/A

Affected Packages

Software From version Fixed in
kernel 6.18.0 6.18.2
unknown

References

Similar Threats

Free Vulnerability Check

Is your site affected by CVE-2025-68740?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against CVE-2025-68740 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.