PT-2025-18463 · Linux+3 · Linux Kernel+3

Published

2025-05-01

·

Updated

2026-05-26

·

CVE-2025-37782

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A slab-out-of-bounds issue has been resolved in the Linux kernel's hfs subsystem. The issue was reported by Syzbot and occurred in the hfs bnode read key function. The problem was caused by an invalid key length, which led to out-of-bounds memory access. To fix this, a check for key length has been added to hfs bnode read key to prevent out-of-bounds memory access. If the key length is invalid, the key buffer is cleared, improving stability and reliability.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

BDU:2026-03406
CVE-2025-37782
DLA-4178-1
DLA-4193-1
ECHO-5F0F-D427-D39A
OESA-2025-1570
OESA-2025-1571
OESA-2025-1572
OESA-2025-1573
SUSE-SU-2025:01964-1
SUSE-SU-2025:01965-1
SUSE-SU-2025:01983-1
SUSE-SU-2025:02000-1
SUSE-SU-2025:02254-1
SUSE-SU-2025:02307-1
SUSE-SU-2025:02333-1
SUSE-SU-2025:02923-1
SUSE-SU-2025:20408-1
SUSE-SU-2025:20413-1
SUSE-SU-2025:20419-1
SUSE-SU-2025:20421-1
SUSE-SU-2025_01964-1
SUSE-SU-2025_01965-1
SUSE-SU-2025_01983-1
SUSE-SU-2025_02000-1
SUSE-SU-2025_02254-1
SUSE-SU-2025_02307-1
SUSE-SU-2025_02333-1

Affected Products

Debian
Linux Kernel
Red Os
Suse