Updated: 2026-01-27
CWE: CWE-125
Description:
In the Linux kernel, the following vulnerability has been resolved: hfs: fix slab-out-of-bounds in hfs_bnode_read() This patch introduces is_bnode_offset_valid() method that checks the requested offset value. Also, it introduces check_and_correct_requested_length() method that checks and correct the requested length (if it is necessary). These methods are used in hfs_bnode_read(), hfs_bnode_write(), hfs_bnode_clear(), hfs_bnode_copy(), and hfs_bnode_move() with the goal to prevent the access out of allocated memory and triggering the crash.
CVSS3: 7.1
| OS | Vendor version | Errata |
|---|---|---|
| Oracle Linux 7 UEK 6 | 5.4.17-2136.348.3.el7uek | ELSA-2025-20663 |
| Oracle Linux 8 UEK 6 | 5.4.17-2136.348.3.el8uek | ELSA-2025-20663 |
| Debian 11 | 5.10.244-1 | DLA-4327-1 |
| Ubuntu 22.04 | 5.15.0-163.173 | USN-7909-1 |
| Ubuntu 22.04 AWS | 5.15.0-1097.104 | USN-7909-1 |
| Debian 11 cloud | 5.10.244-1 | DLA-4327-1 |
| Debian 12 | 6.1.153-1 | DSA-6009-1 |
| OS | Original kernel version | State |
|---|---|---|
| Oracle Linux 7 UEK 6 |
5.4.17-2011.2.2.el7uek
show all
hide all
5.4.17-2011.1.2.el7uek
5.4.17-2011.3.2.1.el7uek
5.4.17-2011.0.7.el7uek
5.4.17-2011.4.4.el7uek
5.4.17-2011.4.6.el7uek
5.4.17-2011.5.3.el7uek
5.4.17-2011.6.2.el7uek
5.4.17-2011.7.4.el7uek
5.4.17-2036.100.6.1.el7uek
5.4.17-2036.101.2.el7uek
5.4.17-2036.102.0.2.el7uek
5.4.17-2036.103.3.el7uek
5.4.17-2036.103.3.1.el7uek
5.4.17-2036.104.4.el7uek
5.4.17-2036.104.5.el7uek
5.4.17-2102.200.13.el7uek
5.4.17-2102.201.3.el7uek
5.4.17-2102.202.5.el7uek
5.4.17-2102.203.5.el7uek
5.4.17-2102.203.6.el7uek
5.4.17-2102.204.4.2.el7uek
5.4.17-2102.204.4.3.el7uek
5.4.17-2102.204.4.4.el7uek
5.4.17-2102.205.7.2.el7uek
5.4.17-2102.205.7.3.el7uek
5.4.17-2102.206.1.el7uek
5.4.17-2136.300.7.el7uek
5.4.17-2136.301.1.2.el7uek
5.4.17-2136.301.1.4.el7uek
5.4.17-2136.302.6.1.el7uek
5.4.17-2136.302.7.2.el7uek
5.4.17-2136.302.7.2.1.el7uek
5.4.17-2136.301.1.3.el7uek
5.4.17-2136.302.7.2.2.el7uek
5.4.17-2136.302.7.2.3.el7uek
5.4.17-2136.304.4.1.el7uek
5.4.17-2136.304.4.2.el7uek
5.4.17-2136.304.4.3.el7uek
5.4.17-2136.304.4.4.el7uek
5.4.17-2136.304.4.5.el7uek
5.4.17-2136.305.5.3.el7uek
5.4.17-2136.305.5.4.el7uek
5.4.17-2136.305.5.5.el7uek
5.4.17-2136.306.1.3.el7uek
5.4.17-2136.307.3.1.el7uek
5.4.17-2136.307.3.2.el7uek
5.4.17-2136.307.3.4.el7uek
5.4.17-2136.307.3.5.el7uek
5.4.17-2136.308.7.el7uek
5.4.17-2136.307.3.6.el7uek
5.4.17-2136.308.9.el7uek
5.4.17-2136.309.5.el7uek
5.4.17-2136.309.5.1.el7uek
5.4.17-2136.310.7.el7uek
5.4.17-2136.310.7.1.el7uek
5.4.17-2136.309.4.el7uek
5.4.17-2136.311.6.el7uek
5.4.17-2136.311.6.1.el7uek
5.4.17-2136.312.3.4.el7uek
5.4.17-2136.313.6.el7uek
5.4.17-2136.314.6.2.el7uek
5.4.17-2136.314.6.3.el7uek
5.4.17-2136.315.5.el7uek
5.4.17-2136.316.7.el7uek
5.4.17-2136.315.5.8.el7uek
5.4.17-2136.317.5.3.el7uek
5.4.17-2136.317.5.5.el7uek
5.4.17-2136.318.7.1.el7uek
5.4.17-2136.318.7.2.el7uek
5.4.17-2136.319.1.2.el7uek
5.4.17-2136.319.1.3.el7uek
5.4.17-2136.319.1.4.el7uek
5.4.17-2136.320.7.el7uek
5.4.17-2136.320.7.1.el7uek
5.4.17-2136.321.4.el7uek
5.4.17-2136.322.6.2.el7uek
5.4.17-2136.323.8.el7uek
5.4.17-2136.323.8.1.el7uek
5.4.17-2136.323.8.2.el7uek
5.4.17-2136.321.4.1.el7uek
5.4.17-2136.324.5.3.el7uek
5.4.17-2136.322.6.3.el7uek
5.4.17-2136.325.5.el7uek
5.4.17-2136.325.5.1.el7uek
5.4.17-2136.326.6.el7uek
5.4.17-2136.326.6.1.el7uek
5.4.17-2136.327.2.el7uek
5.4.17-2136.328.3.el7uek
5.4.17-2136.329.3.1.el7uek
5.4.17-2136.322.6.4.el7uek
5.4.17-2136.329.3.2.el7uek
5.4.17-2136.330.7.1.el7uek
5.4.17-2136.331.7.el7uek
5.4.17-2136.322.6.5.el7uek
5.4.17-2136.330.7.4.el7uek
5.4.17-2136.332.5.2.el7uek
5.4.17-2136.333.5.el7uek
5.4.17-2136.330.7.5.el7uek
5.4.17-2136.333.5.1.el7uek
5.4.17-2136.334.6.el7uek
5.4.17-2136.334.6.1.el7uek
5.4.17-2136.335.4.el7uek
5.4.17-2136.335.4.1.el7uek
5.4.17-2136.336.5.1.el7uek
5.4.17-2136.337.5.el7uek
5.4.17-2136.337.5.1.el7uek
5.4.17-2136.336.5.3.el7uek
5.4.17-2136.336.5.3.1.el7uek
5.4.17-2136.336.5.3.2.el7uek
5.4.17-2136.338.4.1.el7uek
5.4.17-2136.338.4.2.el7uek
|
Released |
| Oracle Linux 8 UEK 6 | |
In Progress |
| Debian 11 | |
Planned |
| Ubuntu 22.04 | |
Planned |
| Ubuntu 22.04 AWS | |
Planned |
| Debian 11 cloud | |
Planned |
| Debian 12 | |
Planned |