Review reviewHigh

CVE-2025-68803

Linux Linux, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP

In the Linux kernel, the following vulnerability has been resolved: NFSD: NFSv4 file creation neglects setting ACL An NFSv4 client that sets an ACL with a named principal during file creation retrieves the ACL afterwards, and finds that it is only a default ACL (based on the mode bits) and not the ACL that was requested during file creation. This violates RFC 8881 section 6.4.1.3: "the ACL attribute is set as given". The issue occurs in nfsd_create_setattr(), which calls nfsd_attrs_valid() to determine whether to call nfsd_setattr(). However, nfsd_attrs_valid() checks only for iattr changes...

CVSS
8
EPSS
0.37%
29.5% percentile
CISA KEV
Not listed
Published
2026.01.14
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability0.37%
Technical severityCVSS 8

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: NFSD: NFSv4 file creation neglects setting ACL An NFSv4 client that sets an ACL with a named principal during file creation retrieves the ACL afterwards, and finds that it is only a default ACL (based on the mode bits) and not the ACL that was requested during file creation. This violates RFC 8881 section 6.4.1.3: "the ACL attribute is set as given". The issue occurs in nfsd_create_setattr(), which calls nfsd_attrs_valid() to determine whether to call nfsd_setattr(). However, nfsd_attrs_valid() checks only for iattr changes...

Affected product and versions

Product
Linux Linux, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP
Affected versions
>= c5409ce523af40d5c3019717bc5b4f72038d48be < c182e1e0b7640f6bcc0c5ca8d473f7c57199ea3d, >= d52acd23a327cada5fb597591267cfc09f08bb1d < 75f91534f9acdfef77f8fa094313b7806f801725, >= c0cbe70742f4a70893cd6e5f6b10b6e89b6db95b < 60dbdef2ebc2317266a385e4debdb1bb0e57afe1, >= c0cbe70742f4a70893cd6e5f6b10b6e89b6db95b < 381261f24f4e4b41521c0e5ef5cc0b9a786a9862, >= c0cbe70742f4a70893cd6e5f6b10b6e89b6db95b < bf4e671c651534a307ab2fabba4926116beef8c3, >= c0cbe70742f4a70893cd6e5f6b10b6e89b6db95b < 214b396480061cbc8b16f2c518b2add7fbfa5192, >= c0cbe70742f4a70893cd6e5f6b10b6e89b6db95b < 913f7cf77bf14c13cfea70e89bcb6d0b22239562, >= 5.10.220 < 5.10.248, >= 5.15.154 < 5.15.198, >= 6.0, >= V3.1.6
Fixed versions
No verified fixed-version field is available yet

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux Linux, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
CWE
Not available
CVE-2025-68803 — Linux Linux, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP | SECUFOCUS NOW