PT-2026-20439 · Hfs+1 · Hfs+1

Published

2025-01-01

·

Updated

2026-03-18

·

CVE-2025-71230

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A flaw exists in the Linux kernel related to the handling of sb->s fs info within the HFS filesystem code. A memory leak could occur during the superblock allocation process when transitioning to the new mount API. Specifically, if setup bdev super() fails after a new superblock is allocated by sget fc(), but before hfs fill super() takes ownership of the filesystem-specific s fs info data, the memory associated with sb->s fs info was not properly freed. The issue is addressed by freeing sb->s fs info in the hfs kill super() function.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Related Identifiers

CVE-2025-71230
ECHO-CDDE-600E-3139
OPENSUSE-SU-2026:10387-1

Affected Products

Hfs
Linux Kernel