DNA View

CVE-2025-38715

Low
Low Medium High Critical
CVSS Score
Published: Sep 04, 2025
Last Modified: Nov 03, 2025

Vulnerability Description

In the Linux kernel, the following vulnerability has been resolved:

hfs: fix slab-out-of-bounds in hfs_bnode_read()

This patch introduces is_bnode_offset_valid() method that checks
the requested offset value. Also, it introduces
check_and_correct_requested_length() method that checks and
correct the requested length (if it is necessary). These methods
are used in hfs_bnode_read(), hfs_bnode_write(), hfs_bnode_clear(),
hfs_bnode_copy(), and hfs_bnode_move() with the goal to prevent
the access out of allocated memory and triggering the crash.

Available Security Patches

5 patches available from vendors

View All Patches
Canonical (Ubuntu)

USN-7938-1

USN-7938-1: Linux kernel (Azure) vulnerabilities

Severity
Unknown
Released
Dec 16, 2025
Restart Required
Security Update
Canonical (Ubuntu)

USN-7910-2

USN-7910-2: Linux kernel (Azure) vulnerabilities

Severity
Unknown
Released
Dec 05, 2025
Restart Required
Security Update
Canonical (Ubuntu)

USN-7909-4

USN-7909-4: Linux kernel vulnerabilities

Severity
Unknown
Released
Dec 05, 2025
Restart Required
Security Update
Microsoft

2025-Sep-CVE-2025-38715

CVE-2025-38715: hfs: fix slab-out-of-bounds in hfs_bnode_read()

Severity
Unknown
Released
Oct 05, 2025
Security Update
SUSE

CVE-2025-38715

CVE-2025-38715

Severity
Unknown
Released
Sep 22, 2025
Security Update

Severity Details

out of 10.0
Low

Key Information

Published Date
September 04, 2025