SB20251210137 - Improper error handling in Linux kernel hfs
Published: December 10, 2025 Updated: December 12, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper error handling (CVE-ID: CVE-2023-53862)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper error handling within the __hfs_bnode_create() function in fs/hfs/bnode.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/062af3e9930762d1fd22946748d34e0d859e4a8e
- https://git.kernel.org/stable/c/2cab8db14566cf6a516c1f103a60cf6b7f54b1e5
- https://git.kernel.org/stable/c/38d72e6604b9f96dffcc0565090cc01622a37b2a
- https://git.kernel.org/stable/c/3a9065a33988c02789722be612f7c42fb8ebbb22
- https://git.kernel.org/stable/c/8140cdc57bc5844cd5e1392673ec2dbf8fdc6940
- https://git.kernel.org/stable/c/a9dc087fd3c484fd1ed18c5efb290efaaf44ce03
- https://git.kernel.org/stable/c/dc9f78b6d254427a06e568f2887b1011ef3143ef
- https://git.kernel.org/stable/c/eda6879272e4df5456afc36642052ea066f58410
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.4.235