PT-2025-49071 · Linux+3 · Linux Kernel+3

CVE-2025-40244

·

Publicado

2025-08-31

·

Atualizado

2026-05-07

CVSS v2.0

6.0

Média

VetorAV:L/AC:H/Au:S/C:C/I:C/A:C
Nome do Software Vulnerável e Versões Afetadas Versões do kernel Linux anteriores a 6.12.0-rc5
Descrição O kernel Linux contém um problema de valor não inicializado dentro da função hfsplus ext cache extent(). Este problema foi identificado pelo syzbot e pode levar a um pânico do kernel. A causa raiz é uma variável não inicializada usada durante a execução da função hfsplus ext cache extent(), que é chamada por hfsplus file extend(), hfsplus get block(), block write begin int(), cont write begin(), hfsplus write begin(), generic perform write(), generic file write iter(), generic file write iter(), vfs write() e ksys write().
Recomendações Atualize para a versão 6.12.0-rc5 ou posterior do kernel Linux.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2026-01306
CVE-2025-40244
DLA-4404-1
SUSE-SU-2026:0278-1
SUSE-SU-2026:0281-1
SUSE-SU-2026:0293-1
SUSE-SU-2026:0315-1
SUSE-SU-2026:0316-1
SUSE-SU-2026:20477-1
SUSE-SU-2026:20498-1
SUSE-SU-2026:20845-1
SUSE-SU-2026:20876-1
USN-8029-1
USN-8029-2
USN-8029-3
USN-8030-1
USN-8033-1
USN-8033-2
USN-8033-3
USN-8033-4
USN-8033-5
USN-8033-6
USN-8033-7
USN-8033-8
USN-8034-1
USN-8034-2
USN-8048-1
USN-8095-1
USN-8095-2
USN-8095-3
USN-8095-4
USN-8095-5
USN-8100-1
USN-8125-1
USN-8126-1
USN-8141-1
USN-8163-1
USN-8163-2
USN-8165-1
USN-8243-1
USN-8261-1

Produtos afetados

Debian
Linuxmint
Linux Kernel
Ubuntu