Executive brief
A vulnerability was identified in the Linux kernel's HFS+ file system driver, which is used to read and write disks formatted for Apple computers. An error in how the system handles internal file structures could allow a local user to cause a system crash or potentially access restricted memory. This could lead to a total system outage or the exposure of sensitive data handled by the kernel.
Technical details
A slab-out-of-bounds read vulnerability exists in the Linux kernel's HFS+ file system implementation. The root cause is located in the hfsplus_bmap_alloc function, which fails to validate that record offsets and lengths retrieved from B-tree nodes are within the bounds of the allocated node_size. An attacker with local access could potentially trigger this by providing a specially crafted HFS+ filesystem image. If the offset or length exceeds the node size, the kernel may access memory pages outside the intended range, leading to a kernel crash (DoS) or potential information disclosure. The vulnerability has been addressed by introducing proper validation checks (is_bnode_offset_valid) before memory access occurs.
Affected products
- Linux Linux Kernel versions prior to 2025-10-29 patches (e.g., 6.17.0-rc2)
Timeline
- 2025-08-18: disclosed: Patch submitted by Yang Chenzhi
- 2025-10-29: patched: Commits merged into stable branches by Greg Kroah-Hartman
- 2025-12-16: advisory: CVE-2025-40349 published
References
- https://git.kernel.org/stable/c/0058d20d76182861dbdd8fd6e2dd8d18d6d3becf
- https://git.kernel.org/stable/c/068a46df3e6acc68fb9db0a6313ab379a11ecd6f
- https://git.kernel.org/stable/c/17ed51cfce6c62cffb97059ef392ad2e0245806e
- https://git.kernel.org/stable/c/40dfe7a4215a1f20842561ffaf5a6f83a987e75b
- https://git.kernel.org/stable/c/418e48cab99c52c1760636a4dbe464bf6db2018b
- https://git.kernel.org/stable/c/4f40a2b3969daf10dca4dea6f6dd0e813f79b227
- https://git.kernel.org/stable/c/738d5a51864ed8d7a68600b8c0c63fe6fe5c4f20