PT-2025-49071 · Linux+3 · Linux Kernel+3
Published
2025-08-31
·
Updated
2026-05-07
·
CVE-2025-40244
CVSS v2.0
6.0
Medium
| Vector | AV:L/AC:H/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to 6.12.0-rc5
Description
The Linux kernel contains an uninitialized value issue within the
hfsplus ext cache extent() function. This issue was identified by syzbot and can lead to a kernel panic. The root cause is an uninitialized variable used during the execution of the hfsplus ext cache extent() function, which is called by hfsplus file extend(), hfsplus get block(), block write begin int(), cont write begin(), hfsplus write begin(), generic perform write(), generic file write iter(), generic file write iter(), vfs write(), and ksys write().Recommendations
Update to Linux kernel version 6.12.0-rc5 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Debian
Linuxmint
Linux Kernel
Ubuntu