PT-2025-6815 · Linux +3 · Linux Kernel +3

Published

2025-01-01

·

Updated

2025-07-16

·

CVE-2025-0927

CVSS v3.1
8.8
VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Name of the Vulnerable Software and Affected Versions:

Linux Kernel versions up to 6.12.0

Ubuntu 22.04 with Linux Kernel 6.5.0-18-generic

Linux Kernel versions 2.x up to 6.13

Description:

The issue is related to a heap overflow vulnerability in the HFS+ file system implementation in the Linux Kernel. An attacker could use a specially crafted file system image that, when mounted, could cause a denial of service or possibly execute arbitrary code. The vulnerability can be exploited to achieve local privilege escalation. Local users can install arbitrary file systems via Udisks2 due to Polkit rules.

Recommendations:

For Linux Kernel versions up to 6.12.0, update to a version that includes the fix for this vulnerability.

For Ubuntu 22.04 with Linux Kernel 6.5.0-18-generic, update to a newer version that includes the fix for this vulnerability.

For Linux Kernel versions 2.x up to 6.13, update to a version that includes the fix for this vulnerability.

As a temporary workaround, consider restricting access to the HFS+ file system implementation until a patch is available.

Avoid using the HFS+ file system implementation until the issue is resolved.

Exploit

Fix

LPE

DoS

Heap Based Buffer Overflow

Buffer Overflow

Memory Corruption

Weakness Enumeration

Related Identifiers

BDU:2025-03186
CVE-2025-0927
LSN-0110-1
USN-7276-1
USN-7288-1
USN-7288-2
USN-7293-1
USN-7296-1
USN-7298-1
USN-7300-1
USN-7301-1
USN-7310-1
USN-7323-1
USN-7323-2
USN-7325-1
USN-7325-2
USN-7325-3
USN-7326-1
USN-7328-1
USN-7328-2
USN-7328-3
USN-7329-1
USN-7331-1
USN-7332-2
USN-7344-1
USN-7344-2
USN-7381-1
USN-7384-1
USN-7384-2
USN-7385-1
USN-7386-1
USN-7388-1
USN-7389-1
USN-7390-1
USN-7392-1
USN-7392-2
USN-7392-3
USN-7392-4
USN-7393-1
USN-7401-1
USN-7403-1
USN-7413-1
USN-7458-1
USN-7463-1
USN-7468-1
USN-7539-1
USN-7540-1

Affected Products

Debian
Linuxmint
Linux Kernel
Ubuntu