Get real-time updates on Telegram
CVE-2025-68740: Linux 2.6.30
CVE-2025-68740 affects azl3 kernel 6.6.117.1-1 on Azure Linux 3.0. CVSS 3.1 base score 5.5 (Microsoft Security Response Center). EPSS 0.00207 (percentile 0.0978), scored 2026-10-05. Fixed version: d14e0ec6a6828ee0dffa163fb5d513c9a21f0a51. Fixed version: f2f4627b74c120fcdd8e1db93bc91f9bbaf46f85. Fixed version: 88cd5fbf5869731be8fc6f7cecb4e0d6ab3d8749. Fixed version: cca3e7df3c0f99542033657ba850b9a6d27f8784. Fixed version: c2238d487a640ae3511e1b6f4640ab27ce10d7f6. Fixed version: de4431faf308d0c533cb386f5fa9af009bc86158. Fixed version: 32952c4f4d1b2deb30dce72ba109da808a9018e1.
Affected technology
Linux · 4af4662fa4a9dc62289c580337ae2506339c4729 to before d14e0ec6a6828ee0dffa163fb5d513c9a21f0a51, 4af4662fa4a9dc62289c580337ae2506339c4729 to before f2f4627b74c120fcdd8e1db93bc91f9bbaf46f85, 4af4662fa4a9dc62289c580337ae2506339c4729 to before 88cd5fbf5869731be8fc6f7cecb4e0d6ab3d8749, 4af4662fa4a9dc62289c580337ae2506339c4729 to before cca3e7df3c0f99542033657ba850b9a6d27f8784, 4af4662fa4a9dc62289c580337ae2506339c4729 to before c2238d487a640ae3511e1b6f4640ab27ce10d7f6, 4af4662fa4a9dc62289c580337ae2506339c4729 to before de4431faf308d0c533cb386f5fa9af009bc86158, 4af4662fa4a9dc62289c580337ae2506339c4729 to before 32952c4f4d1b2deb30dce72ba109da808a9018e1, 4af4662fa4a9dc62289c580337ae2506339c4729 to before 738c9738e690f5cea24a3ad6fd2d9a323cf614f6
Linux
Linux · 2.6.30
Linux
Component: Not specified by the source
Function: incorrectly
File: security/integrity/ima/ima_policy.c
Attack conditions (Microsoft Security Response Center, CVSS 3.1): Local · Low privileges required · No user interaction required
What an attacker can do
Microsoft Security Response Center’s CVSS 3.1 assessment rates confidentiality and integrity impact as none; availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.
- Product
- azl3 kernel 6.6.117.1-1 on Azure Linux 3.0
- CCR priority
- 22.1 /100 (P4)
- CVSS 3.1
- 5.5 /10 · CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H · Microsoft Security Response Center
- EPSS
- 0.00207 · percentile 0.09836 · 2026-10-06
- KEV
- no
Provenance
- FIRST EPSS daily exploit-probability · Source record · observed 2026-10-07 11:53:15.413517+00:00 UTC
- Microsoft MSRC Security Update Guide (CVRF) · Source record · observed 2026-10-04 07:08:49.022374+00:00 UTC
- NVD CVE API 2.0 · Source record · observed 2026-10-05 23:09:08.830529+00:00 UTC
- OSV.dev · Source record · observed 2026-10-07 03:19:31.921362+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2025-68740.html