[SRU][F][PATCH 0/1] CVE-2025-37782

Cengiz Can cengiz.can at canonical.com
Thu May 22 22:58:34 UTC 2025


https://ubuntu.com/security/CVE-2025-37782

[ Impact ]

Attila Szász discovered that the HFS+ file system implementation in the Linux    
Kernel contained a heap overflow vulnerability. An attacker could use a          
specially crafted file system image that, when mounted, could cause a denial of  
service (system crash) or possibly execute arbitrary code.                       
                                                                                 
[ Fix ]                                                                          
                                                                                 
SAUCE patch is getting replaced with upstream commit instead.                    
                                                                                 
Trusty: cherry picked from upstream                                              
Xenial: cherry picked from upstream                                              
Bionic: cherry picked from upstream                                              
Focal: cherry picked from upstream                                               
                                                                                 
Jammy: will receive from stable updates                                          
Noble: will receive from stable updates                                          
Oracular: will receive from stable updates                                       
                                                                                 
[ Test Plan ]                                                                    
                                                                                 
Compile tested only.                                                             
                                                                                 
[ Where Problems Could Occur ]                                                   
                                                                                 
Users that mount legacy Apple HFS+ drives might encounter warnings. 




More information about the kernel-team mailing list