CVE-2025-4003

Severity CVSS v4.0:
MEDIUM
Type:
CWE-404 Improper Resource Shutdown or Release
Publication date:
28/04/2025
Last modified:
29/04/2025

Description

A vulnerability was found in RefindPlusRepo RefindPlus 0.14.2.AB. It has been classified as problematic. This affects the function InternalApfsTranslateBlock of the file Library/RP_ApfsLib/RP_ApfsIo.c. The manipulation leads to null pointer dereference. It is possible to launch the attack on the local host. The patch is named 4d35125ca689a255647e9033dd60c257d26df7cb. It is recommended to apply a patch to fix this issue.