CVE-2023-54130
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
24/12/2025
Last modified:
24/12/2025
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
hfs/hfsplus: avoid WARN_ON() for sanity check, use proper error handling<br />
<br />
Commit 55d1cbbbb29e ("hfs/hfsplus: use WARN_ON for sanity check") fixed<br />
a build warning by turning a comment into a WARN_ON(), but it turns out<br />
that syzbot then complains because it can trigger said warning with a<br />
corrupted hfs image.<br />
<br />
The warning actually does warn about a bad situation, but we are much<br />
better off just handling it as the error it is. So rather than warn<br />
about us doing bad things, stop doing the bad things and return -EIO.<br />
<br />
While at it, also fix a memory leak that was introduced by an earlier<br />
fix for a similar syzbot warning situation, and add a check for one case<br />
that historically wasn&#39;t handled at all (ie neither comment nor<br />
subsequent WARN_ON).
Impact
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/45917be9f0af339a45b4619f31c902d37b8aed59
- https://git.kernel.org/stable/c/82725be426bce0a425cc5e26fbad61ffd29cff03
- https://git.kernel.org/stable/c/90e019006644dad35862cb4aa270f561b0732066
- https://git.kernel.org/stable/c/be01f35efa876eb81cebab2cb0add068b7280ef4
- https://git.kernel.org/stable/c/cb7a95af78d29442b8294683eca4897544b8ef46
- https://git.kernel.org/stable/c/cc2164ada548addfa8ee215196661c3afe0c5154
- https://git.kernel.org/stable/c/da23752d9660ba7a8ca6c5768fd8776f67f59ee7
- https://git.kernel.org/stable/c/f10defb0be6ac42fb6a97b45920d32da6bd6fde8



