cbcvebase.
CVE-2025-40351
published 2025-12-16

CVE-2025-40351: In the Linux kernel, the following vulnerability has been resolved: hfsplus: fix KMSAN uninit-value issue in hfsplus_delete_cat() The syzbot reported issue in…

PriorityP422high7.8
EPSS
0.19%
8.6th percentile
In the Linux kernel, the following vulnerability has been resolved: hfsplus: fix KMSAN uninit-value issue in hfsplus_delete_cat() The syzbot reported issue in hfsplus_delete_cat(): [ 70.682285][ T9333] ===================================================== [ 70.682943][ T9333] BUG: KMSAN: uninit-value in hfsplus_subfolders_dec+0x1d7/0x220 [ 70.683640][ T9333] hfsplus_subfolders_dec+0x1d7/0x220 [ 70.684141][ T9333] hfsplus_delete_cat+0x105d/0x12b0 [ 70.684621][ T9333] hfsplus_rmdir+0x13d/0x310 [ 70.685048][ T9333] vfs_rmdir+0x5ba/0x810 [ 70.685447][ T9333] do_rmdir+0x964/0xea0 [ 70.685833][ T9333] __x64_sys_rmdir+0x71/0xb0 [ 70.686260][ T9333] x64_sys_call+0xcd8/0x3cf0 [ 70.686695][ T9333] do_syscall_64+0xd9/0x1d0 [ 70.687119][ T9333] entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 70.687646][ T9333] [ 70.687856][ T9333] Uninit was stored to memory at: [ 70.688311][ T9333] hfsplus_subfolders_inc+0x1c2/0x1d0 [ 70.688779][ T9333] hfsplus_create_cat+0x148e/0x1800 [ 70.689231][ T9333] hfsplus_mknod+0x27f/0x600 [ 70.689730][ T9333] hfsplus_mkdir+0x5a/0x70 [ 70.690146][ T9333] vfs_mkdir+0x483/0x7a0 [ 70.690545][ T9333] do_mkdirat+0x3f2/0xd30 [ 70.690944][ T9333] __x64_sys_mkdir+0x9a/0xf0 [ 70.691380][ T9333] x64_sys_call+0x2f89/0x3cf0 [ 70.691816][ T9333] do_syscall_64+0xd9/0x1d0 [ 70.692229][ T9333] entry_SYSCALL_64_after_hwframe+0x77/0x7f [ 70.692773][ T9333] [ 70.692990][ T9333] Uninit was stored to memory at: [ 70.693469][ T9333] hfsplus_subfolders_inc+0x1c2/0x1d0 [ 70.693960][ T9333] hfsplus_create_cat+0x148e/0x1800 [ 70.694438][ T9333] hfsplus_fill_super+0x21c1/0x2700 [ 70.694911][ T9333] mount_bdev+0x37b/0x530 [ 70.695320][ T9333] hfsplus_mount+0x4d/0x60 [ 70.695729][ T9333] legacy_get_tree+0x113/0x2c0 [ 70.696167][ T9333] vfs_get_tree+0xb3/0x5c0 [ 70.696588][ T9333] do_new_mount+0x73e/0x1630 [ 70.697013][ T9333] path_mount+0x6e3/0x1eb0 [ 70.697425][ T9333] __se_sys_mount+0x733/0x830 [ 70.697857][ T9333] __x64_sys_mount+0xe4/0x150 [ 70.698269][ T9333] x64_sys_call+0x26

Affected

30 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.158-1 (bookworm)linux 6.1.158-1 (bookworm)
linuxlinux
linuxlinux>= d7d673a591701f131e53d4fd4e2b9352f1316642 < a2bee43b451615531ae6f3cf45054f02915ef885a2bee43b451615531ae6f3cf45054f02915ef885
linuxlinux>= d7d673a591701f131e53d4fd4e2b9352f1316642 < b07630afe1671096dc64064190cae3b6165cf6e4b07630afe1671096dc64064190cae3b6165cf6e4
linuxlinux>= d7d673a591701f131e53d4fd4e2b9352f1316642 < 9df3c241fbf69edce968b20eeeeb3f6da34af0419df3c241fbf69edce968b20eeeeb3f6da34af041
linuxlinux>= d7d673a591701f131e53d4fd4e2b9352f1316642 < 1b9e5ade272f8be6421c9eea4c4f6810180017f91b9e5ade272f8be6421c9eea4c4f6810180017f9
linuxlinux>= d7d673a591701f131e53d4fd4e2b9352f1316642 < 2bb8bc99b1a7a46d83f95c46f530305f6df84eaf2bb8bc99b1a7a46d83f95c46f530305f6df84eaf
linuxlinux>= d7d673a591701f131e53d4fd4e2b9352f1316642 < 295527bfdefd5bf31ec8218e2891a65777141d05295527bfdefd5bf31ec8218e2891a65777141d05
linuxlinux>= d7d673a591701f131e53d4fd4e2b9352f1316642 < 4891bf2b09c313622a6e07d7f108aa5e123c768d4891bf2b09c313622a6e07d7f108aa5e123c768d
linuxlinux>= d7d673a591701f131e53d4fd4e2b9352f1316642 < 9b3d15a758910bb98ba8feb4109d99cc67450ee49b3d15a758910bb98ba8feb4109d99cc67450ee4
linuxlinux_kernel>= 0 < 5.10.247-15.10.247-1
linuxlinux_kernel>= 0 < 6.1.158-16.1.158-1
linuxlinux_kernel>= 0 < 6.12.57-16.12.57-1
linuxlinux_kernel>= 0 < 6.17.6-16.17.6-1
linuxlinux_kernel>= 0 < 5.15.0-170.1805.15.0-170.180
linuxlinux_kernel>= 0 < 6.8.0-106.1066.8.0-106.106
linuxlinux_kernel>= 0 < 6.17.0-14.146.17.0-14.14
linuxlinux_kernel>= 3.14.0 < 5.4.3015.4.301
linuxlinux_kernel>= 5.11.0 < 5.15.1965.15.196
linuxlinux_kernel>= 5.16.0 < 6.1.1586.1.158
linuxlinux_kernel>= 5.5.0 < 5.10.2465.10.246
linuxlinux_kernel>= 6.13.0 < 6.17.66.17.6
linuxlinux_kernel>= 6.2.0 < 6.6.1156.6.115
linuxlinux_kernel>= 6.7.0 < 6.12.566.12.56
ubuntulinux-aws

CVSS provenance

osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_redhat5.5LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.