U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2025-0927

Change History

CVE Modified by kernel.org 4/08/2025 4:15:14 AM

Action Type Old Value New Value
Changed Description
In the Linux kernel, the following vulnerability has been found:
               
A heap overflow in the hfs and hfsplus filesystems can happen if a user mounts a manually crafted filesystem.
               
At this point in time, it is not fixed in any released kernel version, this is a stop-gap report to notify that kernel.org is now the owner of this CVE id.      
               
The Linux kernel CVE team has been assigned CVE-2025-0927 as it was incorrectly created by a different CNA that really should have known better to not have done this.to this issue.
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Filesystem bugs due to corrupt images are not considered a CVE for any filesystem that is only mountable by CAP_SYS_ADMIN in the initial user namespace. That includes delegated mounting.
Removed CVSS V3.1
CISA-ADP: AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

								
						
Removed CVSS V3.1
Canonical Ltd.: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

								
						
Removed CWE
Canonical Ltd.: CWE-787

								
						
Removed Reference
CISA-ADP: https://ssd-disclosure.com/ssd-advisory-linux-kernel-hfsplus-slab-out-of-bounds-write/

								
						
Removed Reference
Canonical Ltd.: https://ubuntu.com/security/CVE-2025-0927

								
						
Removed Reference
Canonical Ltd.: https://ubuntu.com/security/notices/USN-7276-1

								
						
Removed Reference
kernel.org: https://www.kernel.org/

								
						

CVE Rejected by kernel.org 4/08/2025 4:15:14 AM

Action Type Old Value New Value