CVE-2025-4003
Severity CVSS v4.0:
MEDIUM
Type:
CWE-404
Improper Resource Shutdown or Release
Publication date:
28/04/2025
Last modified:
29/04/2025
Description
A vulnerability was found in RefindPlusRepo RefindPlus 0.14.2.AB. It has been classified as problematic. This affects the function InternalApfsTranslateBlock of the file Library/RP_ApfsLib/RP_ApfsIo.c. The manipulation leads to null pointer dereference. It is possible to launch the attack on the local host. The patch is named 4d35125ca689a255647e9033dd60c257d26df7cb. It is recommended to apply a patch to fix this issue.
Impact
Base Score 4.0
6.80
Severity 4.0
MEDIUM
Base Score 3.x
5.50
Severity 3.x
MEDIUM
Base Score 2.0
4.60
Severity 2.0
MEDIUM
References to Advisories, Solutions, and Tools
- https://github.com/RefindPlusRepo/RefindPlus/commit/4d35125ca689a255647e9033dd60c257d26df7cb
- https://github.com/RefindPlusRepo/RefindPlus/issues/206
- https://github.com/RefindPlusRepo/RefindPlus/issues/206#event-16595888967
- https://vuldb.com/?ctiid_306339=
- https://vuldb.com/?id_306339=
- https://vuldb.com/?submit_558123=



