Linux Kernel Out-of-bounds Write Vulnerability Let Attackers Escalate Privileges

Designated as CVE-2025-0927, this out-of-bounds write vulnerability in the Linux kernel’s HFS+ filesystem driver affects systems running kernels up to version 6.12.0, with Ubuntu 22.04 with Linux Kernel 6.5.0-18-generic confirmed vulnerable. A severe vulnerability in the Linux kernel has remained undetected for nearly two decades, allowing local users to gain root privileges on affected systems. While mounting filesystems typically requires elevated privileges, modern Linux distributions like Ubuntu come with default polkit rules that allow users with active local sessions to mount filesystems through the udisks2 service. Despite previous fuzzing efforts, this particular vulnerability remained undetected, demonstrating that manual code analysis continues to be essential for identifying certain classes of security flaws. Cyber Security News is a Dedicated News Platform For Cyber News, Cyber Attack News, Hacking News & Vulnerability Analysis. This newly discovered vulnerability represents a significant security concern for Linux systems. This vulnerability affects numerous Linux distributions running vulnerable kernel versions. Users and administrators should ensure their systems are updated with the latest security patches to mitigate this threat. According to SSD advisory, the flaw exists in the HFS+ driver, which supports Apple’s legacy file system format that was the primary MacOS X filesystem until replaced by APFS in 2017. Users with active local sessions can exploit it to gain root privileges, potentially compromising the entire system.

This Cyber News was published on cybersecuritynews.com. Publication date: Thu, 20 Mar 2025 07:35:04 +0000


Cyber News related to Linux Kernel Out-of-bounds Write Vulnerability Let Attackers Escalate Privileges

Vulnerability Summary for the Week of March 4, 2024 - Published 2024-03-06 CVSS Score not yet calculated Source & Patch Info CVE-2023-52584416baaa9-dc9f-4396-8d5f-8c081fb06d67416baaa9-dc9f-4396-8d5f-8c081fb06d67416baaa9-dc9f-4396-8d5f-8c081fb06d67416baaa9-dc9f-4396-8d5f-8c081fb06d67 PrimaryVendor - ...
1 year ago Cisa.gov
Vulnerability Summary for the Week of March 11, 2024 - Published 2024-03-15 CVSS Score not yet calculated Source & Patch Info CVE-2021-47111416baaa9-dc9f-4396-8d5f-8c081fb06d67416baaa9-dc9f-4396-8d5f-8c081fb06d67416baaa9-dc9f-4396-8d5f-8c081fb06d67 PrimaryVendor - Product linux - linux Description In the ...
1 year ago Cisa.gov
CVE-2024-36886 - In the Linux kernel, the following vulnerability has been resolved: ...
8 months ago
CVE-2024-26957 - In the Linux kernel, the following vulnerability has been resolved: ...
10 months ago
CVE-2024-26688 - In the Linux kernel, the following vulnerability has been resolved: fs,hugetlb: fix NULL pointer dereference in hugetlbs_fill_super When configuring a hugetlb filesystem via the fsconfig() syscall, there is a possible NULL dereference in ...
11 months ago Tenable.com
CVE-2022-49123 - In the Linux kernel, the following vulnerability has been resolved: ...
3 weeks ago
CVE-2024-44989 - In the Linux kernel, the following vulnerability has been resolved: ...
3 months ago
CVE-2022-48664 - In the Linux kernel, the following vulnerability has been resolved: ...
10 months ago
CVE-2024-55642 - In the Linux kernel, the following vulnerability has been resolved: block: Prevent potential deadlocks in zone write plug error recovery Zone write plugging for handling writes to zones of a zoned block device always execute a zone report whenever a ...
2 months ago Tenable.com
CVE-2022-49248 - In the Linux kernel, the following vulnerability has been resolved: ...
3 weeks ago
CVE-2023-52770 - In the Linux kernel, the following vulnerability has been resolved: f2fs: split initial and dynamic conditions for extent_cache Let's allocate the extent_cache tree without dynamic conditions to avoid a missing condition causing a panic as below. # ...
10 months ago Tenable.com
CVE-2022-48923 - In the Linux kernel, the following vulnerability has been resolved: ...
3 months ago
CVE-2024-56658 - In the Linux kernel, the following vulnerability has been resolved: net: defer final 'struct net' free in netns dismantle Ilya reported a slab-use-after-free in dst_destroy [1] Issue is in xfrm6_net_init() and xfrm4_net_init() : They copy ...
2 months ago Tenable.com
CVE-2020-8023 - A acceptance of Extraneous Untrusted Data With Trusted Data vulnerability in the start script of openldap2 of SUSE Enterprise Storage 5, SUSE Linux Enterprise Debuginfo 11-SP3, SUSE Linux Enterprise Debuginfo 11-SP4, SUSE Linux Enterprise Point of ...
4 years ago
CVE-2024-44946 - In the Linux kernel, the following vulnerability has been resolved: ...
3 months ago
CVE-2022-49156 - In the Linux kernel, the following vulnerability has been resolved: ...
3 weeks ago
CVE-2024-50106 - In the Linux kernel, the following vulnerability has been resolved: nfsd: fix race between laundromat and free_stateid There is a race between laundromat handling of revoked delegations and a client sending free_stateid operation. Laundromat thread ...
4 months ago Tenable.com
CVE-2024-57896 - In the Linux kernel, the following vulnerability has been resolved: btrfs: flush delalloc workers queue before stopping cleaner kthread during unmount During the unmount path, at close_ctree(), we first stop the cleaner kthread, using kthread_stop() ...
2 months ago Tenable.com
Linux Kernel Out-of-bounds Write Vulnerability Let Attackers Escalate Privileges - Designated as CVE-2025-0927, this out-of-bounds write vulnerability in the Linux kernel’s HFS+ filesystem driver affects systems running kernels up to version 6.12.0, with Ubuntu 22.04 with Linux Kernel 6.5.0-18-generic confirmed vulnerable. A ...
1 day ago Cybersecuritynews.com CVE-2025-0927
CVE-2021-47118 - In the Linux kernel, the following vulnerability has been resolved: ...
1 year ago
CVE-2021-47512 - In the Linux kernel, the following vulnerability has been resolved: ...
9 months ago
CVE-2021-46976 - In the Linux kernel, the following vulnerability has been resolved: ...
1 year ago
CVE-2024-42251 - In the Linux kernel, the following vulnerability has been resolved: ...
3 months ago
CVE-2021-47341 - In the Linux kernel, the following vulnerability has been resolved: KVM: mmio: Fix use-after-free Read in kvm_vm_ioctl_unregister_coalesced_mmio BUG: KASAN: use-after-free in kvm_vm_ioctl_unregister_coalesced_mmio+0x7c/0x1ec ...
10 months ago Tenable.com
CVE-2025-21684 - In the Linux kernel, the following vulnerability has been resolved: gpio: xilinx: Convert gpio_lock to raw spinlock irq_chip functions may be called in raw spinlock context. Therefore, we must also use a raw spinlock for our own internal locking. ...
1 month ago Tenable.com

Latest Cyber News


Cyber Trends (last 7 days)