Answer in brief
CVE-2025-68788 records a Unknown severity vulnerability in fsnotify: do not generate ACCESS/MODIFY events on child for special files. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic), Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (generic), Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
Answer in brief
CVE-2025-68788 records a Unknown severity vulnerability in fsnotify: do not generate ACCESS/MODIFY events on child for special files. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic), Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (generic), Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic), Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (generic), Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=72acc854427948efed7a83da27f7dc3239ac9afc <df2711544b050aba703e6da418c53c7dc5d443ca || >=72acc854427948efed7a83da27f7dc3239ac9afc <859bdf438f01d9aa7f84b09c1202d548c7cad9e8 || >=72acc854427948efed7a83da27f7dc3239ac9afc <6a7d7d96eeeab7af2bd01afbb3d9878a11a13d91 || >=72acc854427948efed7a83da27f7dc3239ac9afc <e0643d46759db8b84c0504a676043e5e341b6c81 || >=72acc854427948efed7a83da27f7dc3239ac9afc <82f7416bcbd951549e758d15fc1a96a5afc2e900 || >=72acc854427948efed7a83da27f7dc3239ac9afc <7a93edb23bcf07a3aaf8b598edfc2faa8fbcc0b6 || >=72acc854427948efed7a83da27f7dc3239ac9afc <635bc4def026a24e071436f4f356ea08c0eed6ff | df2711544b050aba703e6da418c53c7dc5d443ca, 859bdf438f01d9aa7f84b09c1202d548c7cad9e8, 6a7d7d96eeeab7af2bd01afbb3d9878a11a13d91, e0643d46759db8b84c0504a676043e5e341b6c81, 82f7416bcbd951549e758d15fc1a96a5afc2e900, 7a93edb23bcf07a3aaf8b598edfc2faa8fbcc0b6, 635bc4def026a24e071436f4f356ea08c0eed6ff |
| Linux/Linuxgeneric | 2.6.36 | Not reported |
| Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFPgeneric | >=V3.1.6 <* | * |
| Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFPgeneric | >=V3.1.6 <* | * |
| Siemens/SIPLUS S7-1500 CPU 1518-4 PN/DP MFPgeneric | >=V3.1.6 <* | * |
Published upstream
Jan 13, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Jul 14, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Jul 14, 2026
In the Linux kernel, the following vulnerability has been resolved: fsnotify: do not generate ACCESS/MODIFY events on child for special files inotify/fanotify do not allow users with no read access to a file to subscribe to events (e.g. IN_ACCESS/IN_MODIFY), but they do allow the same user to subscribe for watching events on children when the user has access to the parent directory (e.g. /dev). Users with no read access to a file but with read access to its parent directory can still stat the file and see if it was accessed/modified via atime/mtime change. The same is not true for special files (e.g. /dev/null). Users will not generally observe atime/mtime changes when other users read/write to special files, only when someone sets atime/mtime via utimensat(). Align fsnotify events with this stat behavior and do not generate ACCESS/MODIFY events to parent watchers on read/write of special files. The events are still generated to parent watchers on utimensat(). This closes some side-channels that could be possibly used for information exfiltration [1]. [1] https://snee.la/pdf/pubs/file-notification-attacks.pdf
Quoted source text, attributed separately from HOL analysis.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic), Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (generic), Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=72acc854427948efed7a83da27f7dc3239ac9afc <df2711544b050aba703e6da418c53c7dc5d443ca || >=72acc854427948efed7a83da27f7dc3239ac9afc <859bdf438f01d9aa7f84b09c1202d548c7cad9e8 || >=72acc854427948efed7a83da27f7dc3239ac9afc <6a7d7d96eeeab7af2bd01afbb3d9878a11a13d91 || >=72acc854427948efed7a83da27f7dc3239ac9afc <e0643d46759db8b84c0504a676043e5e341b6c81 || >=72acc854427948efed7a83da27f7dc3239ac9afc <82f7416bcbd951549e758d15fc1a96a5afc2e900 || >=72acc854427948efed7a83da27f7dc3239ac9afc <7a93edb23bcf07a3aaf8b598edfc2faa8fbcc0b6 || >=72acc854427948efed7a83da27f7dc3239ac9afc <635bc4def026a24e071436f4f356ea08c0eed6ff | df2711544b050aba703e6da418c53c7dc5d443ca, 859bdf438f01d9aa7f84b09c1202d548c7cad9e8, 6a7d7d96eeeab7af2bd01afbb3d9878a11a13d91, e0643d46759db8b84c0504a676043e5e341b6c81, 82f7416bcbd951549e758d15fc1a96a5afc2e900, 7a93edb23bcf07a3aaf8b598edfc2faa8fbcc0b6, 635bc4def026a24e071436f4f356ea08c0eed6ff |
| Linux/Linuxgeneric | 2.6.36 | Not reported |
| Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFPgeneric | >=V3.1.6 <* | * |
| Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFPgeneric | >=V3.1.6 <* | * |
| Siemens/SIPLUS S7-1500 CPU 1518-4 PN/DP MFPgeneric | >=V3.1.6 <* | * |
Published upstream
Jan 13, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Jul 14, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Jul 14, 2026
In the Linux kernel, the following vulnerability has been resolved: fsnotify: do not generate ACCESS/MODIFY events on child for special files inotify/fanotify do not allow users with no read access to a file to subscribe to events (e.g. IN_ACCESS/IN_MODIFY), but they do allow the same user to subscribe for watching events on children when the user has access to the parent directory (e.g. /dev). Users with no read access to a file but with read access to its parent directory can still stat the file and see if it was accessed/modified via atime/mtime change. The same is not true for special files (e.g. /dev/null). Users will not generally observe atime/mtime changes when other users read/write to special files, only when someone sets atime/mtime via utimensat(). Align fsnotify events with this stat behavior and do not generate ACCESS/MODIFY events to parent watchers on read/write of special files. The events are still generated to parent watchers on utimensat(). This closes some side-channels that could be possibly used for information exfiltration [1]. [1] https://snee.la/pdf/pubs/file-notification-attacks.pdf
Quoted source text, attributed separately from HOL analysis.