First published: Wed Feb 19 2025(Updated: )
Attila Szász discovered that the HFS+ file system implementation in the Linux Kernel contained a heap overflow vulnerability. An attacker could use a specially crafted file system image that, when mounted, could cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2025-0927) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems:
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/linux-image-6.11.0-1010-lowlatency | <6.11.0-1010.11 | 6.11.0-1010.11 |
Ubuntu | =24.10 | |
All of | ||
ubuntu/linux-image-6.11.0-1010-lowlatency-64k | <6.11.0-1010.11 | 6.11.0-1010.11 |
Ubuntu | =24.10 | |
All of | ||
ubuntu/linux-image-6.11.0-18-generic | <6.11.0-18.18 | 6.11.0-18.18 |
Ubuntu | =24.10 | |
All of | ||
ubuntu/linux-image-6.11.0-18-generic-64k | <6.11.0-18.18 | 6.11.0-18.18 |
Ubuntu | =24.10 | |
All of | ||
ubuntu/linux-image-generic | <6.11.0-18.18 | 6.11.0-18.18 |
Ubuntu | =24.10 | |
All of | ||
ubuntu/linux-image-generic-64k | <6.11.0-18.18 | 6.11.0-18.18 |
Ubuntu | =24.10 | |
All of | ||
ubuntu/linux-image-generic-64k-hwe-24.04 | <6.11.0-18.18 | 6.11.0-18.18 |
Ubuntu | =24.10 | |
All of | ||
ubuntu/linux-image-generic-hwe-24.04 | <6.11.0-18.18 | 6.11.0-18.18 |
Ubuntu | =24.10 | |
All of | ||
ubuntu/linux-image-lowlatency | <6.11.0-1010.11 | 6.11.0-1010.11 |
Ubuntu | =24.10 | |
All of | ||
ubuntu/linux-image-lowlatency-64k | <6.11.0-1010.11 | 6.11.0-1010.11 |
Ubuntu | =24.10 | |
All of | ||
ubuntu/linux-image-oem-24.04 | <6.11.0-18.18 | 6.11.0-18.18 |
Ubuntu | =24.10 | |
All of | ||
ubuntu/linux-image-oem-24.04a | <6.11.0-18.18 | 6.11.0-18.18 |
Ubuntu | =24.10 | |
All of | ||
ubuntu/linux-image-virtual | <6.11.0-18.18 | 6.11.0-18.18 |
Ubuntu | =24.10 | |
All of | ||
ubuntu/linux-image-virtual-hwe-24.04 | <6.11.0-18.18 | 6.11.0-18.18 |
Ubuntu | =24.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Contains the following vulnerabilities)
The severity of USN-7276-1 is considered critical due to the heap overflow vulnerability in the HFS+ file system implementation that can lead to denial of service or arbitrary code execution.
To fix USN-7276-1, update to the recommended Linux kernel versions: 6.11.0-1010.11 or 6.11.0-18.18.
USN-7276-1 affects Ubuntu 24.10 and specific Linux kernel packages associated with it.
USN-7276-1 describes a heap overflow vulnerability that could be exploited by an attacker through a specially crafted file system image.
Currently, the best approach for USN-7276-1 is to apply the patch by upgrading to the fixed kernel versions, as no specific workarounds have been noted.