Review reviewHigh

CVE-2025-40082

Linux Linux, linux kernel

In the Linux kernel, the following vulnerability has been resolved: hfsplus: fix slab-out-of-bounds read in hfsplus_uni2asc() BUG: KASAN: slab-out-of-bounds in hfsplus_uni2asc+0xa71/0xb90 fs/hfsplus/unicode.c:186 Read of size 2 at addr ffff8880289ef218 by task syz.6.248/14290 CPU: 0 UID: 0 PID: 14290 Comm: syz.6.248 Not tainted 6.16.4 #1 PREEMPT(full) Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.15.0-1 04/01/2014 Call Trace: <TASK> __dump_stack lib/dump_stack.c:94 [inline] dump_stack_lvl+0x116/0x1b0 lib/dump_stack.c:120 print_address_description mm/kasan/report.c:378 [inlin...

CVSS
7.1
EPSS
0.18%
7.63% percentile
CISA KEV
Not listed
Published
2025.10.28
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability0.18%
Technical severityCVSS 7.1

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: hfsplus: fix slab-out-of-bounds read in hfsplus_uni2asc() BUG: KASAN: slab-out-of-bounds in hfsplus_uni2asc+0xa71/0xb90 fs/hfsplus/unicode.c:186 Read of size 2 at addr ffff8880289ef218 by task syz.6.248/14290 CPU: 0 UID: 0 PID: 14290 Comm: syz.6.248 Not tainted 6.16.4 #1 PREEMPT(full) Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.15.0-1 04/01/2014 Call Trace: <TASK> __dump_stack lib/dump_stack.c:94 [inline] dump_stack_lvl+0x116/0x1b0 lib/dump_stack.c:120 print_address_description mm/kasan/report.c:378 [inlin...

Affected product and versions

Product
Linux Linux, linux kernel
Affected versions
>= ccf0ad56a779e6704c0b27f555dec847f50c7557 < 343fe375a8dd6ee51a193a1c233b999f5ea4d479, >= 13604b1d7e7b125fb428cddbec6b8d92baad25d5 < 782acde47e127c98a113726e2ff8024bd65c0454, >= 291bb5d931c6f3cd7227b913302a17be21cf53b0 < c3db89ea1ed3d540eebe8f3c36e806fb75ee4a1e, >= f7534cbfac0a9ffa4fa17cacc6e8b6446dae24ee < 5b5228964619b180f366940505b77255b1a03929, >= 94458781aee6045bd3d0ad4b80b02886b9e2219b < 857aefc70d4ae3b9bf1ae67434d27d0f79f80c9e, >= 94458781aee6045bd3d0ad4b80b02886b9e2219b < bea3e1d4467bcf292c8e54f080353d556d355e26, >= 73f7da507d787b489761a0fa280716f84fa32b2f, >= 76a4c6636a69d69409aa253b049b1be717a539c5, >= 6f93694bcbc2c2ab3e01cd8fba2f296faf34e6b9, >= 1ca69007e52a73bd8b84b988b61b319816ca8b01, >= 5.15.190 < 5.15.200, >= 6.1.149 < 6.1.163, >= 6.6.103 < 6.6.124, >= 6.12.43 < 6.12.70, >= 5.4.297 < 5.5, >= 5.10.241 < 5.11, >= 6.15.11 < 6.16, >= 6.16.2 < 6.17, >= 6.17, >= 6.16.2 < 6.17.3
Fixed versions
5.5, 5.11, 5.15.200, 6.1.163, 6.6.124, 6.12.70, 6.16, 6.17.3

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux Linux, linux kernel and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
CWE
CWE-125