CVE-2025-71230

In the Linux kernel, the following vulnerability has been resolved: hfs: ensure sb->s_fs_info is always cleaned up When hfs was converted to the new mount api a bug was introduced by changing the allocation pattern of sb->s_fs_info. If setup_bdev_super() fails after a new superblock has been allocated by sget_fc(), but before hfs_fill_super() takes ownership of the filesystem-specific s_fs_info data it was leaked. Fix this by freeing sb->s_fs_info in hfs_kill_super().
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

History

18 Mar 2026, 17:18

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
References () https://git.kernel.org/stable/c/05ce49a902be15dc93854cbfc20161205a9ee446 - () https://git.kernel.org/stable/c/05ce49a902be15dc93854cbfc20161205a9ee446 - Patch
References () https://git.kernel.org/stable/c/399219831514126bc9541e8eadefe02c6fbd9166 - () https://git.kernel.org/stable/c/399219831514126bc9541e8eadefe02c6fbd9166 - Patch
References () https://git.kernel.org/stable/c/46c1d56ad321fb024761abd9af61a0cb616cf2f6 - () https://git.kernel.org/stable/c/46c1d56ad321fb024761abd9af61a0cb616cf2f6 - Patch
CPE cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
CWE NVD-CWE-noinfo
First Time Linux
Linux linux Kernel

23 Feb 2026, 04:15

Type Values Removed Values Added
References
  • () https://git.kernel.org/stable/c/05ce49a902be15dc93854cbfc20161205a9ee446 -
Summary
  • (es) En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta: hfs: asegurar que sb->s_fs_info siempre se limpia Cuando hfs fue convertido a la nueva API de montaje, se introdujo un error al cambiar el patrón de asignación de sb->s_fs_info. Si setup_bdev_super() falla después de que un nuevo superbloque ha sido asignado por sget_fc(), pero antes de que hfs_fill_super() tome posesión de los datos s_fs_info específicos del sistema de archivos, se filtraba. Esto se soluciona liberando sb->s_fs_info en hfs_kill_super().

18 Feb 2026, 16:22

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-18 16:22

Updated : 2026-03-18 17:18


NVD link : CVE-2025-71230

Mitre link : CVE-2025-71230

CVE.ORG link : CVE-2025-71230


JSON object : View

Products Affected

linux

  • linux_kernel