Executive brief
A vulnerability was identified in the Linux kernel's HFS+ file system driver, which is used to read and write disks formatted for Apple computers. An attacker with local access to the system could potentially read sensitive information from the computer's memory or cause the system to crash. This issue occurs when the system compares file names on an HFS+ formatted drive.
Technical details
A slab-out-of-bounds read vulnerability exists in the hfsplus_strcasecmp() function within the Linux kernel's HFS+ file system driver (fs/hfsplus/unicode.c). The issue is triggered during string comparison operations, specifically when the logic fails to properly bound memory access while processing Unicode strings, leading to a read beyond the allocated buffer in the kmalloc-2k cache. A local attacker can exploit this by interacting with a specially crafted HFS+ filesystem, potentially leading to a kernel crash (DoS) or information disclosure. The vulnerability has been patched in multiple stable branches of the Linux kernel.
Affected products
- Linux Linux Kernel versions before 6.11.5, 6.6.58, 6.1.114, 5.15.169, 5.10.228, 5.4.285, 4.19.323
Timeline
- 2025-09-19: patched: Initial fix authored by Viacheslav Dubeyko
- 2025-10-30: disclosed: CVE-2025-40088 published
References
- https://git.kernel.org/stable/c/42520df65bf67189541a425f7d36b0b3e7bd7844
- https://git.kernel.org/stable/c/4bc081ba6c52b0c88c92701e3fbc33c7e2277afb
- https://git.kernel.org/stable/c/4f5ab4a9c6abd8b0d713cc2b7b041bc10d70f241
- https://git.kernel.org/stable/c/586c75dfd1d265c4150f6529debb85c9d62e101f
- https://git.kernel.org/stable/c/603158d4efa98a13a746bd586c20f194f4a31ec8
- https://git.kernel.org/stable/c/7ab44236b32ed41eb0636797e8e8e885a2f3b18a
- https://git.kernel.org/stable/c/b47a75b6f762321f9eb6f31aab7bce47a37063b7