Review reviewHigh

CVE-2025-68764

Linux Linux, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP

In the Linux kernel, the following vulnerability has been resolved: NFS: Automounted filesystems should inherit ro,noexec,nodev,sync flags When a filesystem is being automounted, it needs to preserve the user-set superblock mount options, such as the "ro" flag.

CVSS
7.8
EPSS
0.13%
2.68% percentile
CISA KEV
Not listed
Published
2026.01.05
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability0.13%
Technical severityCVSS 7.8

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: NFS: Automounted filesystems should inherit ro,noexec,nodev,sync flags When a filesystem is being automounted, it needs to preserve the user-set superblock mount options, such as the "ro" flag.

Affected product and versions

Product
Linux Linux, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP
Affected versions
>= f2aedb713c284429987dc66c7aaf38decfc8da2a < a3dc6c40bcab1a888d5c0d134ccc0746b4c98929, >= f2aedb713c284429987dc66c7aaf38decfc8da2a < ba1495aefd22fcf0746a2a3025c95d766d7cde4d, >= f2aedb713c284429987dc66c7aaf38decfc8da2a < c09070b4def1b34e473a746c6a5331ccb80902c1, >= f2aedb713c284429987dc66c7aaf38decfc8da2a < dce10c59211e5cd763a62ea01e79b82a629811e3, >= f2aedb713c284429987dc66c7aaf38decfc8da2a < 612cc98698d667df804792f0c47d4e501e66da29, >= f2aedb713c284429987dc66c7aaf38decfc8da2a < 4b296944e632cf4c6a4cc8e2585c6451eae47b1b, >= f2aedb713c284429987dc66c7aaf38decfc8da2a < df9b003a2ecacc7218486fbb31fe008c93097d5f, >= f2aedb713c284429987dc66c7aaf38decfc8da2a < 8675c69816e4276b979ff475ee5fac4688f80125, >= 5.6, >= V3.1.6
Fixed versions
No verified fixed-version field is available yet

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux Linux, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE
Not available
CVE-2025-68764 — Linux Linux, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP | SECUFOCUS NOW