SB2025090479 - NULL pointer dereference in Linux kernel hfs
Published: September 4, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) NULL pointer dereference (CVE-ID: CVE-2025-38716)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to NULL pointer dereference within the hfs_ext_keycmp() function in fs/hfs/extent.c, within the hfs_btree_open() function in fs/hfs/btree.c, within the hfs_find_init() function in fs/hfs/bfind.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/4f032979b63ad52e08aadf0faeac34ed35133ec0
- https://git.kernel.org/stable/c/5d8b249527362e0ccafcaf76b3bec2a0d2aa1498
- https://git.kernel.org/stable/c/6e20e10064fdc43231636fca519c15c013a8e3d6
- https://git.kernel.org/stable/c/736a0516a16268995f4898eded49bfef077af709
- https://git.kernel.org/stable/c/b918c17a1934ac6309b0083f41d4e9d8fb3bb46c