Executive brief
A vulnerability in the Linux kernel's HFS+ filesystem driver could allow a local user to crash the system. By providing a specially crafted or corrupted HFS+ storage volume with inconsistent header information, an attacker can trigger a kernel panic. This results in a complete denial of service for the affected machine.
Technical details
A reachable assertion (CWE-617) exists in the hfsplus_create_attributes_file() function within fs/hfsplus/xattr.c. When a volume header contains erroneous values that do not match the actual filesystem state, hfsplus_fill_super() may incorrectly assume the attributes file does not exist. Subsequent calls to hfsplus_create_attributes_file() then encounter an unexpected file size, triggering a BUG_ON() macro and causing a kernel panic. The fix replaces the BUG_ON() with proper error handling (-EIO) and a log message. This is exploitable by a local user with the ability to mount a malformed HFS+ filesystem.
Affected products
- Linux Linux Kernel 3.13 to 5.4.297, 5.5 to 5.10.241, 5.11 to 5.15.190, 5.16 to 6.1.149, 6.2 to 6.6.103, 6.7 to 6.12.43, 6.13 to 6.15.11, 6.16 to 6.16.2
Timeline
- 2025-07-15: patched: Initial patch authored by Tetsuo Handa
- 2025-09-04: disclosed: CVE-2025-38712 published
References
- https://git.kernel.org/stable/c/03cd1db1494cf930e2fa042c9c13e32bffdb4eba
- https://git.kernel.org/stable/c/1bb8da27ff15e346d4bc9e248e819c9a88ebf9d6
- https://git.kernel.org/stable/c/9046566fa692f88954dac8c510f37ee17a15fdb7
- https://git.kernel.org/stable/c/b3359392b75395a31af739a761f48f4041148226
- https://git.kernel.org/stable/c/bb0eea8e375677f586ad11c12e2525ed3fc698c2
- https://git.kernel.org/stable/c/c7c6363ca186747ebc2df10c8a1a51e66e0e32d9
- https://git.kernel.org/stable/c/ce5e387f396cbb5c061d9837abcac731e9e06f4d