Executive brief
A vulnerability in the Linux kernel's JFS filesystem component can cause a system crash. When the filesystem is used in read-only mode, certain internal management tasks are not properly set up, leading to a critical error when the system tries to close a file transaction. This could allow a local user to cause a denial-of-service by crashing the operating system.
Technical details
A flaw exists in the JFS (Journaled File System) transaction manager within the Linux kernel. During initialization in `txInit()`, the waitqueue for the first transaction block (`TxBlock[0]`) is skipped because the initialization loop incorrectly starts at index 1. On read-only filesystems, `txBegin()` returns a transaction ID (tid) of 0; subsequent calls to `txEnd(0)` attempt to access the uninitialized waitqueue in `TxBlock[0]`. This results in a 'non-static key' lockdep warning and a kernel panic (system crash). The issue is resolved by ensuring the initialization loop in `txInit()` starts at index 0.
Affected products
- Linux Linux Kernel 5.4.255 to 5.4.302, 5.10.192 to 5.10.247, 5.15.123 to 5.15.197, 6.1.42 to 6.1.159
Timeline
- 2025-12-16: advisory: CVE-2025-68168 published by NVD/kernel.org
References
- https://git.kernel.org/stable/c/038861414ab383b41dd35abbf9ff0ef715592d53
- https://git.kernel.org/stable/c/2a9575a372182ca075070b3cd77490dcf0c951e7
- https://git.kernel.org/stable/c/300b072df72694ea330c4c673c035253e07827b8
- https://git.kernel.org/stable/c/8cae9cf23e0bd424ac904e753639a587543ce03a
- https://git.kernel.org/stable/c/a2aa97cde9857f881920635a2e3d3b11769619c5
- https://git.kernel.org/stable/c/cbf2f527ae4ca7c7dabce42e85e8deb58588a37e
- https://git.kernel.org/stable/c/d2dd7ca05a11685c314e62802a55e8d67a90e974