{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2025-40082",
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "state": "PUBLISHED",
        "assignerShortName": "Linux",
        "dateReserved": "2025-04-16T07:20:57.161Z",
        "datePublished": "2025-10-28T11:48:45.975Z",
        "dateUpdated": "2026-08-05T12:07:37.878Z"
    },
    "containers": {
        "cna": {
            "providerMetadata": {
                "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
                "shortName": "Linux",
                "dateUpdated": "2026-08-05T12:07:37.878Z"
            },
            "descriptions": [
                {
                    "lang": "en",
                    "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nhfsplus: fix slab-out-of-bounds read in hfsplus_uni2asc()\n\nBUG: KASAN: slab-out-of-bounds in hfsplus_uni2asc+0xa71/0xb90 fs/hfsplus/unicode.c:186\nRead of size 2 at addr ffff8880289ef218 by task syz.6.248/14290\n\nCPU: 0 UID: 0 PID: 14290 Comm: syz.6.248 Not tainted 6.16.4 #1 PREEMPT(full)\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.15.0-1 04/01/2014\nCall Trace:\n <TASK>\n __dump_stack lib/dump_stack.c:94 [inline]\n dump_stack_lvl+0x116/0x1b0 lib/dump_stack.c:120\n print_address_description mm/kasan/report.c:378 [inline]\n print_report+0xca/0x5f0 mm/kasan/report.c:482\n kasan_report+0xca/0x100 mm/kasan/report.c:595\n hfsplus_uni2asc+0xa71/0xb90 fs/hfsplus/unicode.c:186\n hfsplus_listxattr+0x5b6/0xbd0 fs/hfsplus/xattr.c:738\n vfs_listxattr+0xbe/0x140 fs/xattr.c:493\n listxattr+0xee/0x190 fs/xattr.c:924\n filename_listxattr fs/xattr.c:958 [inline]\n path_listxattrat+0x143/0x360 fs/xattr.c:988\n do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]\n do_syscall_64+0xcb/0x4c0 arch/x86/entry/syscall_64.c:94\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\nRIP: 0033:0x7fe0e9fae16d\nCode: 02 b8 ff ff ff ff c3 66 0f 1f 44 00 00 f3 0f 1e fa 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48\nRSP: 002b:00007fe0eae67f98 EFLAGS: 00000246 ORIG_RAX: 00000000000000c3\nRAX: ffffffffffffffda RBX: 00007fe0ea205fa0 RCX: 00007fe0e9fae16d\nRDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000200000000000\nRBP: 00007fe0ea0480f0 R08: 0000000000000000 R09: 0000000000000000\nR10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000\nR13: 00007fe0ea206038 R14: 00007fe0ea205fa0 R15: 00007fe0eae48000\n </TASK>\n\nAllocated by task 14290:\n kasan_save_stack+0x24/0x50 mm/kasan/common.c:47\n kasan_save_track+0x14/0x30 mm/kasan/common.c:68\n poison_kmalloc_redzone mm/kasan/common.c:377 [inline]\n __kasan_kmalloc+0xaa/0xb0 mm/kasan/common.c:394\n kasan_kmalloc include/linux/kasan.h:260 [inline]\n __do_kmalloc_node mm/slub.c:4333 [inline]\n __kmalloc_noprof+0x219/0x540 mm/slub.c:4345\n kmalloc_noprof include/linux/slab.h:909 [inline]\n hfsplus_find_init+0x95/0x1f0 fs/hfsplus/bfind.c:21\n hfsplus_listxattr+0x331/0xbd0 fs/hfsplus/xattr.c:697\n vfs_listxattr+0xbe/0x140 fs/xattr.c:493\n listxattr+0xee/0x190 fs/xattr.c:924\n filename_listxattr fs/xattr.c:958 [inline]\n path_listxattrat+0x143/0x360 fs/xattr.c:988\n do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]\n do_syscall_64+0xcb/0x4c0 arch/x86/entry/syscall_64.c:94\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\nWhen hfsplus_uni2asc is called from hfsplus_listxattr,\nit actually passes in a struct hfsplus_attr_unistr*.\nThe size of the corresponding structure is different from that of hfsplus_unistr,\nso the previous fix (94458781aee6) is insufficient.\nThe pointer on the unicode buffer is still going beyond the allocated memory.\n\nThis patch introduces two warpper functions hfsplus_uni2asc_xattr_str and\nhfsplus_uni2asc_str to process two unicode buffers,\nstruct hfsplus_attr_unistr* and struct hfsplus_unistr* respectively.\nWhen ustrlen value is bigger than the allocated memory size,\nthe ustrlen value is limited to an safe size."
                }
            ],
            "metrics": [
                {
                    "cvssV3_1": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H",
                        "baseScore": 7.1,
                        "baseSeverity": "HIGH"
                    },
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "AV:L - The attacker-controlled input is an on-disk HFS+ attributes B-tree key, and the vulnerable conversion is reached through the ordinary local `listxattr()`/`llistxattr()` syscall on a mounted volume; there is no network or remote-peer input path. Local rather than Physical because the volume can be attached locally via a loop device and the trigger is a plain local syscall.\nAC:L - The `length` field of the `hfsplus_attr_unistr` key name is written verbatim by the attacker in the crafted image and was clamped to 255 instead of 127, so the 256-byte overread fires deterministically on the first `listxattr()` call. No race, no heap grooming, and no condition outside the attacker's control.\nPR:L - Nothing on the `path_listxattrat` → `vfs_listxattr` → `hfsplus_listxattr` → `hfsplus_uni2asc` path performs any capability check — the only `capable(CAP_SYS_ADMIN)` test (`can_list()`) runs after the out-of-bounds conversion and merely filters `trusted.*` names. Any unprivileged local user who can traverse an HFS+ volume (e.g. one udisks2-automounted from attacker-supplied removable media) triggers it.\nUI:N - In the automount/kiosk scenario the volume is mounted by the system on device insertion with no victim action, and the attacker then issues the `listxattr()` himself; likewise an attacker with loop-mount access performs every step. Choosing the higher-severity option where the mount could otherwise be attributed to a victim.\nS:U - The out-of-bounds read, the leaked bytes, and any resulting fault all stay within the kernel's own security authority. No VM, IOMMU, or sandbox boundary is crossed.\nC:H - This is not a bounded few-byte read: up to 256 bytes past the `kzalloc(536)` key allocation are consumed, NLS-converted into `strbuf`, and copied out to userspace by `copy_name()` plus the `copy_to_user()` in `listxattr()`, giving a direct kernel-heap disclosure channel rather than a mere oracle. On slub_debug/KASAN/KFENCE and hardened configurations those bytes are live redzone/stale slab content adjacent to the allocation.\nI:N - `hfsplus_uni2asc()` only dereferences and converts the input; the output writes are bounded by `*len_p` via `nls->uni2char()` returning `-ENAMETOOLONG`. There is no out-of-bounds write, no type confusion, and no mechanism to modify kernel memory or hijack control flow.\nA:H - The slab out-of-bounds read is a guaranteed KASAN/KFENCE report and, with `panic_on_warn`/`panic_on_oops`, a kernel panic; where the overread crosses a KFENCE guard page it faults outright. It also leaves the xattr listing returning `-EIO`/garbage, rendering the volume's attribute handling unusable, and is repeatable at will by an unprivileged user."
                        }
                    ]
                }
            ],
            "affected": [
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "unaffected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "fs/hfsplus/dir.c",
                        "fs/hfsplus/hfsplus_fs.h",
                        "fs/hfsplus/unicode.c",
                        "fs/hfsplus/xattr.c"
                    ],
                    "versions": [
                        {
                            "version": "ccf0ad56a779e6704c0b27f555dec847f50c7557",
                            "lessThan": "343fe375a8dd6ee51a193a1c233b999f5ea4d479",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "13604b1d7e7b125fb428cddbec6b8d92baad25d5",
                            "lessThan": "782acde47e127c98a113726e2ff8024bd65c0454",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "291bb5d931c6f3cd7227b913302a17be21cf53b0",
                            "lessThan": "c3db89ea1ed3d540eebe8f3c36e806fb75ee4a1e",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "f7534cbfac0a9ffa4fa17cacc6e8b6446dae24ee",
                            "lessThan": "5b5228964619b180f366940505b77255b1a03929",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "94458781aee6045bd3d0ad4b80b02886b9e2219b",
                            "lessThan": "857aefc70d4ae3b9bf1ae67434d27d0f79f80c9e",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "94458781aee6045bd3d0ad4b80b02886b9e2219b",
                            "lessThan": "bea3e1d4467bcf292c8e54f080353d556d355e26",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "73f7da507d787b489761a0fa280716f84fa32b2f",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "76a4c6636a69d69409aa253b049b1be717a539c5",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "6f93694bcbc2c2ab3e01cd8fba2f296faf34e6b9",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "1ca69007e52a73bd8b84b988b61b319816ca8b01",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "5.15.190",
                            "lessThan": "5.15.200",
                            "status": "affected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.1.149",
                            "lessThan": "6.1.163",
                            "status": "affected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.6.103",
                            "lessThan": "6.6.124",
                            "status": "affected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.12.43",
                            "lessThan": "6.12.70",
                            "status": "affected",
                            "versionType": "semver"
                        },
                        {
                            "version": "5.4.297",
                            "lessThan": "5.5",
                            "status": "affected",
                            "versionType": "semver"
                        },
                        {
                            "version": "5.10.241",
                            "lessThan": "5.11",
                            "status": "affected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.15.11",
                            "lessThan": "6.16",
                            "status": "affected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.16.2",
                            "lessThan": "6.17",
                            "status": "affected",
                            "versionType": "semver"
                        }
                    ]
                },
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "affected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "fs/hfsplus/dir.c",
                        "fs/hfsplus/hfsplus_fs.h",
                        "fs/hfsplus/unicode.c",
                        "fs/hfsplus/xattr.c"
                    ],
                    "versions": [
                        {
                            "version": "6.17",
                            "status": "affected"
                        },
                        {
                            "version": "0",
                            "lessThan": "6.17",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "5.15.200",
                            "lessThanOrEqual": "5.15.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.1.163",
                            "lessThanOrEqual": "6.1.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.6.124",
                            "lessThanOrEqual": "6.6.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.12.70",
                            "lessThanOrEqual": "6.12.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.17.3",
                            "lessThanOrEqual": "6.17.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.18",
                            "lessThanOrEqual": "*",
                            "status": "unaffected",
                            "versionType": "original_commit_for_fix"
                        }
                    ]
                }
            ],
            "cpeApplicability": [
                {
                    "nodes": [
                        {
                            "operator": "OR",
                            "negate": false,
                            "cpeMatch": [
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.15.190",
                                    "versionEndExcluding": "5.15.200"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "6.1.149",
                                    "versionEndExcluding": "6.1.163"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "6.6.103",
                                    "versionEndExcluding": "6.6.124"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "6.12.43",
                                    "versionEndExcluding": "6.12.70"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "6.17",
                                    "versionEndExcluding": "6.17.3"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "6.17",
                                    "versionEndExcluding": "6.18"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.4.297"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.10.241"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "6.15.11"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "6.16.2"
                                }
                            ]
                        }
                    ]
                }
            ],
            "references": [
                {
                    "url": "https://git.kernel.org/stable/c/343fe375a8dd6ee51a193a1c233b999f5ea4d479"
                },
                {
                    "url": "https://git.kernel.org/stable/c/782acde47e127c98a113726e2ff8024bd65c0454"
                },
                {
                    "url": "https://git.kernel.org/stable/c/c3db89ea1ed3d540eebe8f3c36e806fb75ee4a1e"
                },
                {
                    "url": "https://git.kernel.org/stable/c/5b5228964619b180f366940505b77255b1a03929"
                },
                {
                    "url": "https://git.kernel.org/stable/c/857aefc70d4ae3b9bf1ae67434d27d0f79f80c9e"
                },
                {
                    "url": "https://git.kernel.org/stable/c/bea3e1d4467bcf292c8e54f080353d556d355e26"
                }
            ],
            "title": "hfsplus: fix slab-out-of-bounds read in hfsplus_uni2asc()",
            "x_generator": {
                "engine": "bippy-1.2.0"
            }
        }
    }
}