Junglewise Threat Intelligence

CVE-2025-68788: Linux Kernel information disclosure in fsnotify special file events

CVE-2025-68788 · Severity: info · CVSS 0 · Published 2026-01-13

Technologies: Linux Kernel, Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP. Vendors: Linux, Siemens.

Executive brief

A vulnerability in the Linux kernel's file notification system (fsnotify) could allow a local user to monitor activity on special system files, such as those in the /dev directory, even if they do not have permission to read those files. By watching the parent directory, an attacker can receive alerts whenever another user or process interacts with these files. This creates a side-channel that could be used to leak sensitive information about system operations or user activity.

Technical details

A vulnerability in the Linux kernel's fsnotify subsystem (specifically inotify and fanotify) allows users with read access to a parent directory to receive ACCESS and MODIFY events for special files (e.g., /dev/null) even if they lack read permissions for the files themselves. While standard files reveal access via atime/mtime changes visible through stat(), special files typically do not, making these notification events an unexpected side-channel. An attacker can exploit this to monitor interactions with sensitive device nodes or special files. The fix modifies fs/notify/fsnotify.c to suppress these events for special files unless they are explicitly triggered by metadata changes like utimensat(). Patching is available in various stable kernel branches.

Affected products

  • Linux Linux Kernel 72acc854427948efed7a83da27f7dc3239ac9afc to df2711544b050aba703e6da418c53c7dc5d443ca
  • Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP V3.1.6 and later

Timeline

  • 2025-12-07: other: Initial patch authored by Amir Goldstein
  • 2026-01-13: advisory: CVE published to NVD

References

Related threats