{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/fscrypt/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"id":"CVE-2026-68147"}],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["fscrypt"],"_cs_severities":["medium"],"_cs_tags":["vulnerability","kernel","linux","informational"],"_cs_type":"threat","_cs_vendors":[],"content_html":"\u003cp\u003eCVE-2026-68147 relates to a vulnerability identified within the fscrypt subsystem of the Linux kernel. The issue originates in the fscrypt_get_devices() function, which previously performed dynamic memory allocation. This approach introduced potential risks for memory-related stability issues, such as memory exhaustion or corruption, during the retrieval of device information. Security updates have been issued to refactor this function to eliminate dynamic allocation, thereby enhancing the robustness of the filesystem encryption infrastructure. Organizations utilizing kernel versions incorporating this vulnerable function should evaluate their exposure and prioritize kernel updates as recommended by their distribution vendors.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation or accidental triggering of this vulnerability could lead to local denial-of-service conditions or system instability due to memory corruption. While this vulnerability is primarily a concern for system integrity and availability, it does not currently involve documented active exploitation in the wild.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMonitor upstream Linux kernel security advisories for the specific patch release addressing CVE-2026-68147.\u003c/li\u003e\n\u003cli\u003eApply kernel security updates provided by the respective Linux distribution vendor to all systems utilizing fscrypt functionality.\u003c/li\u003e\n\u003cli\u003eAudit systems for fscrypt configuration to assess the surface area of potential impact within the environment.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-11T10:13:31Z","date_published":"2026-08-11T10:13:31Z","id":"https://feed.craftedsignal.io/briefs/2026-08-11-cve-2026-68147/","summary":"CVE-2026-68147 addresses a memory management vulnerability in the Linux kernel fscrypt subsystem within the fscrypt_get_devices function, where improper dynamic allocation could lead to memory corruption or exhaustion.","title":"Vulnerability in Linux Kernel fscrypt Subsystem","url":"https://feed.craftedsignal.io/briefs/2026-08-11-cve-2026-68147/"},{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"id":"CVE-2026-68148"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["fscrypt"],"_cs_severities":["medium"],"_cs_tags":["vulnerability","linux","kernel","informational"],"_cs_type":"advisory","_cs_vendors":["Linux Foundation"],"content_html":"\u003cp\u003eThe Microsoft Security Response Center has released information regarding CVE-2026-68148, a vulnerability identified within the fscrypt subsystem of the Linux kernel. The issue originates in the find_or_insert_direct_key() function, where a critical superblock check is missing. This oversight affects how direct keys are processed and validated against the filesystem superblock. If left unpatched, this vulnerability could be leveraged to cause system instability or result in integrity issues during filesystem operations. Defenders should monitor for kernel updates provided by their Linux distribution vendors to address this logic error, as it relates to internal kernel memory and object handling rather than externally reachable network services.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability poses a risk to filesystem integrity and system stability. If exploited, an attacker capable of triggering this specific code path could potentially cause kernel-level instability or unintended filesystem behavior. The scope of impact is limited to systems utilizing the fscrypt subsystem for filesystem-level encryption.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMonitor Linux distribution security advisories for the inclusion of the fix for CVE-2026-68148.\u003c/li\u003e\n\u003cli\u003eApply the relevant kernel security patches to all affected Linux systems running encrypted filesystems utilizing fscrypt.\u003c/li\u003e\n\u003cli\u003ePrioritize patching for systems where untrusted users or processes have the ability to interact with mounted encrypted volumes.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-11T09:57:46Z","date_published":"2026-08-11T09:57:46Z","id":"https://feed.craftedsignal.io/briefs/2026-08-fscrypt-superblock-check/","summary":"A vulnerability in the Linux kernel fscrypt subsystem exists due to a missing superblock check in the find_or_insert_direct_key function, potentially impacting filesystem integrity.","title":"Missing Superblock Check in fscrypt find_or_insert_direct_key","url":"https://feed.craftedsignal.io/briefs/2026-08-fscrypt-superblock-check/"}],"language":"en","title":"CraftedSignal Threat Feed - Fscrypt","version":"https://jsonfeed.org/version/1.1"}