Security readout for executives and security teams
Plain-English summary
A Linux HFS+ filesystem flaw can read beyond an allocated kernel memory object during file deletion processing. Because kernel memory corruption can affect confidentiality, integrity, and availability, exposed systems should receive a corrected vendor kernel promptly. The supplied evidence does not establish remote reachability or active exploitation.
Executive priority
Treat as a high-priority kernel update for systems that use or may process HFS+ content. Accelerate remediation on multi-user or media-processing systems. Lower the priority only after confirming HFS+ is unavailable and vendor assessment shows the installed kernel is unaffected.
Technical view
CVE-2025-38714 is a slab-out-of-bounds read in hfsplus_bnode_read(), observed by KASAN while unlinking an HFS+ object and deleting attributes. The supplied CVSS 3.1 score is 7.8: local access, low complexity, low privileges, no user interaction, with high confidentiality, integrity, and availability impacts.
Likely exposure
Exposure is most likely where an affected Linux kernel supports and processes HFS+ filesystems. Systems that never mount or otherwise use HFS+ have lower practical exposure. The supplied version data is ambiguous, so confirm affected and corrected package versions with the Linux distribution or appliance vendor.
Exploitation context
The supplied record is not marked as CISA KEV and provides no evidence of active exploitation. Its CVSS vector describes a local, low-privileged attack path. A sanitizer-triggering reproducer exists, but the bundle does not establish reliable privilege escalation, data theft, or remote exploitation.
Researcher notes
The trace records an eight-byte out-of-bounds read in hfsplus_bnode_read(), reached through attribute deletion and unlink handling. Stable-tree fixes are referenced across multiple branches. The bundle is truncated and contains unclear version entries; researchers should use commit ancestry and vendor package mappings instead of interpreting every listed version as a release boundary.
Mitigation direction
Install a vendor-supported kernel containing the applicable stable HFS+ correction.
Check distribution or appliance advisories for exact corrected package versions.
Until patched, restrict untrusted users and services from mounting or processing HFS+ media.
Prioritize shared hosts, appliances, and systems accepting removable or uploaded filesystem images.
Validation and detection
Inventory kernel versions and identify systems where HFS+ support is available or loaded.
Review mount configuration and telemetry for current or historical HFS+ filesystem use.
Map installed packages against vendor advisories and applicable Linux stable fix commits.
After updating, verify the corrected kernel is running following any required reboot.
Monitor kernel logs for HFS+ faults, KASAN reports, crashes, or unexpected reboots.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cve · low confidence lookup
CVE-2025-38714 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
1CVSS vectors
3Timeline events
2ADP providers
13Source links
CVSS vector scores
1 official score
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.