Impact
The kernel flaw appears when hfsplus_delete_cat() processes a corrupted HFS+ catalog entry. It reads the thread name length directly from a B-tree record, then copies that many bytes into a search key structure without first verifying the record is a thread record or that its size matches nodeName.length. This unchecked copy can overrun the buffer and corrupt kernel memory, potentially leading to arbitrary kernel code execution or a system crash.
Affected Systems
All Linux kernels that include HFS+ file system support are potentially affected until the upstream patch that validates the thread record before rebuilding the delete key is applied. The vendor list indicates generic Linux kernels (Linux:Linux) and the CPE points to the Linux kernel; there are no distribution‑specific version restrictions in the data, so the issue applies broadly to any kernel with HFS+ enabled.
Risk and Exploitability
The vulnerability has a CVSS base score of 7.8, indicating high severity, while the EPSS score of less than 1 % suggests a low probability of exploitation in the wild. The flaw requires the kernel to read a malformed or malicious HFS+ image—such as by mounting a corrupted partition—which limits the attack surface to local or privileged actors. Attackers could achieve local privilege escalation or denial‑of‑service by triggering the buffer overflow; remote exploitation would likely need a prior compromise that allows an adversary to present a corrupted HFS+ image to the target.
OpenCVE Enrichment
Debian DLA
Debian DSA