PT-2025-49071 · Linux+3 · Linux Kernel+3

Published

2025-08-31

·

Updated

2026-05-07

·

CVE-2025-40244

CVSS v2.0

6.0

Medium

VectorAV:L/AC:H/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.12.0-rc5
Description The Linux kernel contains an uninitialized value issue within the hfsplus ext cache extent() function. This issue was identified by syzbot and can lead to a kernel panic. The root cause is an uninitialized variable used during the execution of the hfsplus ext cache extent() function, which is called by hfsplus file extend(), hfsplus get block(), block write begin int(), cont write begin(), hfsplus write begin(), generic perform write(), generic file write iter(), generic file write iter(), vfs write(), and ksys write().
Recommendations Update to Linux kernel version 6.12.0-rc5 or later.

Exploit

Fix

Weakness Enumeration

Related Identifiers

BDU:2026-01306
CVE-2025-40244
DLA-4404-1
SUSE-SU-2026:0278-1
SUSE-SU-2026:0281-1
SUSE-SU-2026:0293-1
SUSE-SU-2026:0315-1
SUSE-SU-2026:0316-1
SUSE-SU-2026:20477-1
SUSE-SU-2026:20498-1
SUSE-SU-2026:20845-1
SUSE-SU-2026:20876-1
USN-8029-1
USN-8029-2
USN-8029-3
USN-8030-1
USN-8033-1
USN-8033-2
USN-8033-3
USN-8033-4
USN-8033-5
USN-8033-6
USN-8033-7
USN-8033-8
USN-8034-1
USN-8034-2
USN-8048-1
USN-8095-1
USN-8095-2
USN-8095-3
USN-8095-4
USN-8095-5
USN-8100-1
USN-8125-1
USN-8126-1
USN-8141-1
USN-8163-1
USN-8163-2
USN-8165-1
USN-8243-1
USN-8261-1

Affected Products

Debian
Linuxmint
Linux Kernel
Ubuntu