Answer in brief
CVE-2025-68264 records a Unknown severity vulnerability in ext4: refresh inline data size before write operations. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic), Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (generic), Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic), Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (generic), Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=67cf5b09a46f72e048501b84996f2f77bc42e947 <54ab81ae5f218452e64470cd8a8139bb5880fe2b || >=67cf5b09a46f72e048501b84996f2f77bc42e947 <43bf001f0fe4e59bba47c897505222f959f4a1cc || >=67cf5b09a46f72e048501b84996f2f77bc42e947 <89c2c41f0974e530b2d032c3695095aa0559adb1 || >=67cf5b09a46f72e048501b84996f2f77bc42e947 <1687a055a555347b002f406676a1aaae4668f242 || >=67cf5b09a46f72e048501b84996f2f77bc42e947 <210ac60a86a3ad2c76ae60e0dc71c34af6e7ea0b || >=67cf5b09a46f72e048501b84996f2f77bc42e947 <ca43ea29b4c4d2764aec8a26cffcfb677a871e6e || >=67cf5b09a46f72e048501b84996f2f77bc42e947 <58df743faf21ceb1880f930aa5dd428e2a5e415d || >=67cf5b09a46f72e048501b84996f2f77bc42e947 <892e1cf17555735e9d021ab036c36bc7b58b0e3b | 54ab81ae5f218452e64470cd8a8139bb5880fe2b, 43bf001f0fe4e59bba47c897505222f959f4a1cc, 89c2c41f0974e530b2d032c3695095aa0559adb1, 1687a055a555347b002f406676a1aaae4668f242, 210ac60a86a3ad2c76ae60e0dc71c34af6e7ea0b, ca43ea29b4c4d2764aec8a26cffcfb677a871e6e, 58df743faf21ceb1880f930aa5dd428e2a5e415d, 892e1cf17555735e9d021ab036c36bc7b58b0e3b |
| Linux/Linuxgeneric | 3.8 | Not reported |
| Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFPgeneric | >=V3.1.6 <* | * |
| Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFPgeneric | >=V3.1.6 <* | * |
| Siemens/SIPLUS S7-1500 CPU 1518-4 PN/DP MFPgeneric | >=V3.1.6 <* | * |
Published upstream
Dec 16, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 8, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Jul 14, 2026
In the Linux kernel, the following vulnerability has been resolved: ext4: refresh inline data size before write operations The cached ei->i_inline_size can become stale between the initial size check and when ext4_update_inline_data()/ext4_create_inline_data() use it. Although ext4_get_max_inline_size() reads the correct value at the time of the check, concurrent xattr operations can modify i_inline_size before ext4_write_lock_xattr() is acquired. This causes ext4_update_inline_data() and ext4_create_inline_data() to work with stale capacity values, leading to a BUG_ON() crash in ext4_write_inline_data(): kernel BUG at fs/ext4/inline.c:1331! BUG_ON(pos + len > EXT4_I(inode)->i_inline_size); The race window: 1. ext4_get_max_inline_size() reads i_inline_size = 60 (correct) 2. Size check passes for 50-byte write 3. [Another thread adds xattr, i_inline_size changes to 40] 4. ext4_write_lock_xattr() acquires lock 5. ext4_update_inline_data() uses stale i_inline_size = 60 6. Attempts to write 50 bytes but only 40 bytes actually available 7. BUG_ON() triggers Fix this by recalculating i_inline_size via ext4_find_inline_data_nolock() immediately after acquiring xattr_sem. This ensures ext4_update_inline_data() and ext4_create_inline_data() work with current values that are protected from concurrent modifications. This is similar to commit a54c4613dac1 ("ext4: fix race writing to an inline_data file while its xattrs are changing") which fixed i_inline_off staleness. This patch addresses the related i_inline_size staleness issue.
Quoted source text, attributed separately from HOL analysis.