Junglewise Threat Intelligence

CVE-2025-40349: Linux Kernel slab-out-of-bounds read in hfsplus_bmap_alloc

CVE-2025-40349 · Severity: high · CVSS 7.8 · Published 2025-12-16

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's HFS+ file system driver, which is used to read and write disks formatted for Apple computers. An error in how the system handles internal file structures could allow a local user to cause a system crash or potentially access restricted memory. This could lead to a total system outage or the exposure of sensitive data handled by the kernel.

Technical details

A slab-out-of-bounds read vulnerability exists in the Linux kernel's HFS+ file system implementation. The root cause is located in the hfsplus_bmap_alloc function, which fails to validate that record offsets and lengths retrieved from B-tree nodes are within the bounds of the allocated node_size. An attacker with local access could potentially trigger this by providing a specially crafted HFS+ filesystem image. If the offset or length exceeds the node size, the kernel may access memory pages outside the intended range, leading to a kernel crash (DoS) or potential information disclosure. The vulnerability has been addressed by introducing proper validation checks (is_bnode_offset_valid) before memory access occurs.

Affected products

  • Linux Linux Kernel versions prior to 2025-10-29 patches (e.g., 6.17.0-rc2)

Timeline

  • 2025-08-18: disclosed: Patch submitted by Yang Chenzhi
  • 2025-10-29: patched: Commits merged into stable branches by Greg Kroah-Hartman
  • 2025-12-16: advisory: CVE-2025-40349 published

References

Related threats