Executive brief
A vulnerability was identified in the Linux kernel's HFS file system driver, which is used to read and write older Apple-formatted disks. A flaw in how the system manages memory when checking for available file identifiers could allow a local user to cause a system crash or potentially gain unauthorized access to data. This issue has been resolved in recent kernel updates.
Technical details
A use-after-free (UAF) vulnerability exists in the hfs_correct_next_unused_CNID() function within fs/hfs/catalog.c of the Linux kernel. The vulnerability is caused by a reference counting error where hfs_bnode_put(node) is called to release a node reference before the code attempts to access node->prev on the subsequent line. A local attacker with the ability to trigger HFS catalog operations could exploit this race condition or memory reuse to cause a kernel panic or achieve local privilege escalation. The fix reorders the operations to ensure the node is accessed before its reference is released. Patches are available in the stable kernel branches.
Affected products
- Linux Linux Kernel 6.18, 6.18.2, 6.19
Timeline
- 2025-10-03: other: Vulnerability fixed in source code by Dan Carpenter
- 2026-01-05: advisory: CVE-2025-68761 published