All of lore.kernel.org
 help / color / mirror / Atom feed
* CVE-2025-0927: heap overflow in the hfs and hfsplus filesystems with manually crafted filesystem
@ 2025-03-30 18:55 Greg Kroah-Hartman
  2025-04-02  6:51 ` [PATCH 1/2] published: CVE-2025-0927: Fix up JSON schema Siddh Raman Pant
  2025-04-08  8:06 ` REJECTED: CVE-2025-0927: heap overflow in the hfs and hfsplus filesystems with manually crafted filesystem Greg Kroah-Hartman
  0 siblings, 2 replies; 29+ messages in thread
From: Greg Kroah-Hartman @ 2025-03-30 18:55 UTC (permalink / raw)
  To: linux-cve-announce; +Cc: Greg Kroah-Hartman

Description
===========

In the Linux kernel, the following vulnerability has been found:

A heap overflow in the hfs and hfsplus filesystems can happen if a user
mounts a manually crafted filesystem.

At this point in time, it is not fixed in any released kernel version,
this is a stop-gap report to notify that kernel.org is now the owner of
this CVE id.

The Linux kernel CVE team has been assigned CVE-2025-0927 as it was
incorrectly created by a different CNA that really should have known
better to not have done this.to this issue.


Affected and fixed versions
===========================

	All released kernel versions are affected.

Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.

Unaffected versions might change over time as fixes are backported to
older supported kernel versions.  The official CVE entry at
	https://cve.org/CVERecord/?id=CVE-2025-0927
will be updated if fixes are backported, please check that for the most
up to date information about this issue.


Affected files
==============

The file(s) affected by this issue are:
	fs/hfs/bnode.c
	fs/hfsplus/bnode.c


Mitigation
==========

Do not allow users to mount untrusted filesystem images.

^ permalink raw reply	[flat|nested] 29+ messages in thread

end of thread, other threads:[~2025-05-23 12:51 UTC | newest]

Thread overview: 29+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2025-03-30 18:55 CVE-2025-0927: heap overflow in the hfs and hfsplus filesystems with manually crafted filesystem Greg Kroah-Hartman
2025-04-02  6:51 ` [PATCH 1/2] published: CVE-2025-0927: Fix up JSON schema Siddh Raman Pant
2025-04-02  6:51   ` [PATCH 2/2] published: CVE-2025-0927: Rearrange fields in JSON Siddh Raman Pant
2025-04-02  7:06     ` Greg Kroah-Hartman
2025-04-02  7:06   ` [PATCH 1/2] published: CVE-2025-0927: Fix up JSON schema Greg Kroah-Hartman
2025-04-02  7:16     ` Siddh Raman Pant
2025-04-02  7:41       ` gregkh
2025-04-02  7:07   ` Greg Kroah-Hartman
2025-04-08  8:06 ` REJECTED: CVE-2025-0927: heap overflow in the hfs and hfsplus filesystems with manually crafted filesystem Greg Kroah-Hartman
2025-05-09  7:20   ` Dmitry Vyukov
2025-05-09  7:34     ` Greg KH
2025-05-09  7:47       ` Dmitry Vyukov
2025-05-09  7:55         ` Greg KH
2025-05-09  8:03           ` Dmitry Vyukov
2025-05-09 12:10             ` Theodore Ts'o
2025-05-09 13:18               ` Attila Szasz
2025-05-09 13:37                 ` Greg KH
2025-05-09 14:17                 ` Theodore Ts'o
2025-05-12 13:22               ` Dmitry Vyukov
2025-05-12 14:44                 ` Theodore Ts'o
2025-05-12 17:17                   ` Attila Szasz
2025-05-13  7:09                   ` Dmitry Vyukov
2025-05-13 12:05                     ` Theodore Ts'o
2025-05-13 16:09                       ` Dmitry Vyukov
2025-05-13 21:43                         ` Theodore Ts'o
2025-05-14  4:53                           ` Dmitry Vyukov
2025-05-21  8:20           ` Dmitry Vyukov
2025-05-23 12:51             ` Greg KH
2025-05-09 14:05         ` Theodore Ts'o

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.