Junglewise Threat Intelligence

CVE-2025-38712: Linux Kernel reachable assertion in hfsplus_create_attributes_file

CVE-2025-38712 · Severity: medium · CVSS 5.5 · Published 2025-09-04

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's HFS+ filesystem driver could allow a local user to crash the system. By providing a specially crafted or corrupted HFS+ storage volume with inconsistent header information, an attacker can trigger a kernel panic. This results in a complete denial of service for the affected machine.

Technical details

A reachable assertion (CWE-617) exists in the hfsplus_create_attributes_file() function within fs/hfsplus/xattr.c. When a volume header contains erroneous values that do not match the actual filesystem state, hfsplus_fill_super() may incorrectly assume the attributes file does not exist. Subsequent calls to hfsplus_create_attributes_file() then encounter an unexpected file size, triggering a BUG_ON() macro and causing a kernel panic. The fix replaces the BUG_ON() with proper error handling (-EIO) and a log message. This is exploitable by a local user with the ability to mount a malformed HFS+ filesystem.

Affected products

  • Linux Linux Kernel 3.13 to 5.4.297, 5.5 to 5.10.241, 5.11 to 5.15.190, 5.16 to 6.1.149, 6.2 to 6.6.103, 6.7 to 6.12.43, 6.13 to 6.15.11, 6.16 to 6.16.2

Timeline

  • 2025-07-15: patched: Initial patch authored by Tetsuo Handa
  • 2025-09-04: disclosed: CVE-2025-38712 published

References

Related threats