binfmt_misc: restore write access before closing files opened by open_exec()
Published Dec 16, 2025
4.7
MEDIUMCVSS 3.1
EPSS 0.20%
Description
bm_register_write() opens an executable file using open_exec(), which internally calls do_open_execat() and denies write access on the file to avoid modification while it is being executed.
However, when an error occurs, bm_register_write() closes the file using filp_close() directly. This does not restore the write permission, which may cause subsequent write operations on the same file to fail.
Fix this by calling exe_file_allow_write_access() before filp_close() to restore the write permission properly.
Affected products
-
- Version StatusaffectedConstraints-
- Version StatusaffectedConstraints-
- Version StatusaffectedConstraints-
- Version StatusaffectedConstraints-
- Version StatusaffectedConstraints-
- Version StatusaffectedConstraints-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 4.14.226StatusaffectedConstraints<4.15
- Version 4.19.181StatusaffectedConstraints<4.20
- Version 4.9.262StatusaffectedConstraints<4.10
- Version 5.10.24StatusaffectedConstraints<5.11
- Version 5.11.7StatusaffectedConstraints<5.12
- Version 5.4.106StatusaffectedConstraints<5.5
- Version
-
- Version 5.12StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<5.12
- Version 5.15.209StatusunaffectedConstraints<=5.15.*
- Version 6.1.167StatusunaffectedConstraints<=6.1.*
- Version 6.12.78StatusunaffectedConstraints<=6.12.*
- Version 6.17.9StatusunaffectedConstraints<=6.17.*
- Version 6.18StatusunaffectedConstraints<=*
- Version 6.6.130StatusunaffectedConstraints<=6.6.*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Linux | Linux | unaffected |
| |||||||||||||||||||||||||||||||||||||||
| Linux | Linux | unaffected |
| |||||||||||||||||||||||||||||||||||||||
| Linux | Linux | affected |
|
No data.
No data.
Red Hat Enterprise Linux 10
kernel
Fix deferred
Red Hat Enterprise Linux 6
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel
Fix deferred
Red Hat Enterprise Linux 9
kernel-rt
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | kernel | Fix deferred | n/a |
| Red Hat Enterprise Linux 6 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This bug affects file permission state handling rather than security boundaries. The impact is limited to denial of write access on specific files after binfmt_misc registration errors, which is a reliability issue rather than a security vulnerability.
References (12)
- https://access.redhat.com/security/cve/CVE-2025-68239 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2422758 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-203657 Advisory
- https://git.kernel.org/stable/c/480ac88431703f2adbb8e6b5bd73c3f3cf9f3d7f
- https://git.kernel.org/stable/c/54274ff90488b6c0f595a6518faed3cf0bc966eb
- https://git.kernel.org/stable/c/6cce7bc7fac8471c832696720d9c8f2a976d9c54
- https://git.kernel.org/stable/c/90f601b497d76f40fa66795c3ecf625b6aced9fd
- https://git.kernel.org/stable/c/e785f552ab04dbca01d31f0334f4561240b04459
- https://git.kernel.org/stable/c/fbab8c08e1a6dbaef81e22d672a7647553101d16
- https://lore.kernel.org/linux-cve-announce/2025121630-CVE-2025-68239-f7a4@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2025-68239
- https://www.cve.org/CVERecord?id=CVE-2025-68239
Change history (0)
No recorded changes yet.