Executive brief
The Linux kernel's HFS filesystem driver contains a vulnerability in its filename character conversion function that can write beyond allocated memory boundaries. An attacker who can create a specially crafted HFS filesystem with abnormally long filenames could trigger a kernel memory corruption, potentially leading to a denial of service or system crash.
Technical details
The vulnerability is an out-of-bounds (OOB) write in the hfs_asc2mac() function in fs/hfs/trans.c, which converts ASCII filenames to HFS (Macintosh) format. The function fails to check the destination buffer length (dstlen) during character conversion, allowing writes to continue past the 31-byte maximum HFS filename length (HFS_NAMELEN). When processing a source filename longer than 31 bytes, the loop condition only checked srclen > 0 without verifying dstlen, causing heap buffer overflow. The fix adds a dstlen check to the while loop condition to prevent writing beyond the destination buffer. This vulnerability is triggered when mounting or accessing a malformed HFS filesystem.
Affected products
- Linux Linux kernel affected versions across multiple stable kernels including linux-2.6.x through linux-6.x series
Timeline
- 2022-12-02: disclosed: Vulnerability report submitted by Syzbot
- 2023-01-18: patched: Fix merged upstream (commit c53ed55cb275344086e32a7080a6b19cb183650b) and backported to stable kernels
- 2025-12-24: advisory: CVE-2022-50747 published