cbcvebase.
CVE-2025-71230
published 2026-02-18

CVE-2025-71230: In the Linux kernel, the following vulnerability has been resolved: hfs: ensure sb->s_fs_info is always cleaned up When hfs was converted to the new mount api…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.12%
1.9th percentile
In the Linux kernel, the following vulnerability has been resolved: hfs: ensure sb->s_fs_info is always cleaned up When hfs was converted to the new mount api a bug was introduced by changing the allocation pattern of sb->s_fs_info. If setup_bdev_super() fails after a new superblock has been allocated by sget_fc(), but before hfs_fill_super() takes ownership of the filesystem-specific s_fs_info data it was leaked. Fix this by freeing sb->s_fs_info in hfs_kill_super().

Affected

9 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.18.12-1 (forky)linux 6.18.12-1 (forky)
linuxlinux
linuxlinux>= ffcd06b6d13b72823aba0d7c871f7e4876e7916b < 46c1d56ad321fb024761abd9af61a0cb616cf2f646c1d56ad321fb024761abd9af61a0cb616cf2f6
linuxlinux>= ffcd06b6d13b72823aba0d7c871f7e4876e7916b < 399219831514126bc9541e8eadefe02c6fbd9166399219831514126bc9541e8eadefe02c6fbd9166
linuxlinux>= ffcd06b6d13b72823aba0d7c871f7e4876e7916b < 05ce49a902be15dc93854cbfc20161205a9ee44605ce49a902be15dc93854cbfc20161205a9ee446
linuxlinux_kernel>= 0 < 6.18.12-16.18.12-1
linuxlinux_kernel>= 6.13 < 6.18.116.18.11
linuxlinux_kernel>= 6.19 < 6.19.16.19.1
msrcazl3_kernel_6.6.121.1-1_on_azure_linux_3.0

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
vendor_msrc4.2MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.