Executive brief
A vulnerability exists in the Linux kernel's HFS+ file system driver, which is used to read and write disks formatted for Apple computers. An attacker with local access to the system could exploit this flaw to cause a system crash or potentially access sensitive information from the computer's memory. This could lead to a loss of system availability or unauthorized data exposure.
Technical details
A slab-out-of-bounds read vulnerability was identified in the hfsplus_bnode_read() function within the Linux kernel's HFS+ file system implementation. The issue occurs when the kernel attempts to read data from a B-tree node (bnode) during operations such as hfsplus_delete_cat() or hfsplus_unlink(). KASAN reports indicate a read of size 8 beyond the allocated slab region in kmalloc-192. This is a local vulnerability requiring the ability to perform file system operations on an HFS+ volume. Successful exploitation can result in a kernel oops/denial of service or local information disclosure. Patches have been released across multiple stable kernel branches.
Affected products
- Linux Linux Kernel 6.16.0-rc3
Timeline
- 2025-09-04: advisory: CVE published in NVD
- 2025-08-28: patched: Fix committed to Linux stable tree
References
- https://git.kernel.org/stable/c/032f7ed6717a4cd3714f9801be39fdfc7f1c7644
- https://git.kernel.org/stable/c/291b7f2538920aa229500dbdd6c5f0927a51bc8b
- https://git.kernel.org/stable/c/475d770c19929082aab43337e6c077d0e2043df3
- https://git.kernel.org/stable/c/5ab59229bef6063edf3a6fc2e3e3fd7cd2181b29
- https://git.kernel.org/stable/c/7fa4cef8ea13b37811287ef60674c5fd1dd02ee6
- https://git.kernel.org/stable/c/8583d067ae22b7f32ce5277ca5543ac8bf86a3e5
- https://git.kernel.org/stable/c/a2abd574d2fe22b8464cf6df5abb6f24d809eac0