In the Linux kernel, the following vulnerability has been resolved:
hfsplus: don't use BUGON() in hfspluscreateattributesfile()
When the volume header contains erroneous values that do not reflect the actual state of the filesystem, hfsplusfillsuper() assumes that the attributes file is not yet created, which later results in hitting BUGON() when hfspluscreateattributesfile() is called. Replace this BUG_ON() with -EIO error with a message to suggest running fsck tool.
[
    {
        "signature_version": "v1",
        "target": {
            "function": "hfsplus_create_attributes_file",
            "file": "fs/hfsplus/xattr.c"
        },
        "id": "CVE-2025-38712-0477d470",
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@9046566fa692f88954dac8c510f37ee17a15fdb7",
        "digest": {
            "function_hash": "1325647912185204093573489800882180896",
            "length": 2810.0
        },
        "deprecated": false,
        "signature_type": "Function"
    },
    {
        "signature_version": "v1",
        "target": {
            "function": "hfsplus_create_attributes_file",
            "file": "fs/hfsplus/xattr.c"
        },
        "id": "CVE-2025-38712-106d38b0",
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@ce5e387f396cbb5c061d9837abcac731e9e06f4d",
        "digest": {
            "function_hash": "129993581455223314666122366169433619650",
            "length": 2749.0
        },
        "deprecated": false,
        "signature_type": "Function"
    },
    {
        "signature_version": "v1",
        "target": {
            "function": "hfsplus_create_attributes_file",
            "file": "fs/hfsplus/xattr.c"
        },
        "id": "CVE-2025-38712-330d1856",
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@c7c6363ca186747ebc2df10c8a1a51e66e0e32d9",
        "digest": {
            "function_hash": "129993581455223314666122366169433619650",
            "length": 2749.0
        },
        "deprecated": false,
        "signature_type": "Function"
    },
    {
        "signature_version": "v1",
        "target": {
            "file": "fs/hfsplus/xattr.c"
        },
        "id": "CVE-2025-38712-43b43311",
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@c7c6363ca186747ebc2df10c8a1a51e66e0e32d9",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "337637008272987461766692467184874204434",
                "164857410119348318271743488210841190392",
                "299857197256906545469360148947087129095",
                "220626602264411295320622016003642110814"
            ]
        },
        "deprecated": false,
        "signature_type": "Line"
    },
    {
        "signature_version": "v1",
        "target": {
            "file": "fs/hfsplus/xattr.c"
        },
        "id": "CVE-2025-38712-57dc04df",
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@d768e3ed430e89a699bf89d3214dcbbf4648c939",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "337637008272987461766692467184874204434",
                "164857410119348318271743488210841190392",
                "299857197256906545469360148947087129095",
                "220626602264411295320622016003642110814"
            ]
        },
        "deprecated": false,
        "signature_type": "Line"
    },
    {
        "signature_version": "v1",
        "target": {
            "file": "fs/hfsplus/xattr.c"
        },
        "id": "CVE-2025-38712-7101c252",
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@ce5e387f396cbb5c061d9837abcac731e9e06f4d",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "337637008272987461766692467184874204434",
                "164857410119348318271743488210841190392",
                "299857197256906545469360148947087129095",
                "220626602264411295320622016003642110814"
            ]
        },
        "deprecated": false,
        "signature_type": "Line"
    },
    {
        "signature_version": "v1",
        "target": {
            "function": "hfsplus_create_attributes_file",
            "file": "fs/hfsplus/xattr.c"
        },
        "id": "CVE-2025-38712-788eb736",
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@dee5c668ad71ddbcb4b48d95e8a4f371314ad41d",
        "digest": {
            "function_hash": "129993581455223314666122366169433619650",
            "length": 2749.0
        },
        "deprecated": false,
        "signature_type": "Function"
    },
    {
        "signature_version": "v1",
        "target": {
            "function": "hfsplus_create_attributes_file",
            "file": "fs/hfsplus/xattr.c"
        },
        "id": "CVE-2025-38712-81044ec1",
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@bb0eea8e375677f586ad11c12e2525ed3fc698c2",
        "digest": {
            "function_hash": "1325647912185204093573489800882180896",
            "length": 2810.0
        },
        "deprecated": false,
        "signature_type": "Function"
    },
    {
        "signature_version": "v1",
        "target": {
            "file": "fs/hfsplus/xattr.c"
        },
        "id": "CVE-2025-38712-8cc72f74",
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@03cd1db1494cf930e2fa042c9c13e32bffdb4eba",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "337637008272987461766692467184874204434",
                "164857410119348318271743488210841190392",
                "299857197256906545469360148947087129095",
                "220626602264411295320622016003642110814"
            ]
        },
        "deprecated": false,
        "signature_type": "Line"
    },
    {
        "signature_version": "v1",
        "target": {
            "file": "fs/hfsplus/xattr.c"
        },
        "id": "CVE-2025-38712-8e771535",
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@bb0eea8e375677f586ad11c12e2525ed3fc698c2",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "337637008272987461766692467184874204434",
                "164857410119348318271743488210841190392",
                "299857197256906545469360148947087129095",
                "220626602264411295320622016003642110814"
            ]
        },
        "deprecated": false,
        "signature_type": "Line"
    },
    {
        "signature_version": "v1",
        "target": {
            "function": "hfsplus_create_attributes_file",
            "file": "fs/hfsplus/xattr.c"
        },
        "id": "CVE-2025-38712-9027f7f4",
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@d768e3ed430e89a699bf89d3214dcbbf4648c939",
        "digest": {
            "function_hash": "129993581455223314666122366169433619650",
            "length": 2749.0
        },
        "deprecated": false,
        "signature_type": "Function"
    },
    {
        "signature_version": "v1",
        "target": {
            "function": "hfsplus_create_attributes_file",
            "file": "fs/hfsplus/xattr.c"
        },
        "id": "CVE-2025-38712-92e51d69",
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@1bb8da27ff15e346d4bc9e248e819c9a88ebf9d6",
        "digest": {
            "function_hash": "129993581455223314666122366169433619650",
            "length": 2749.0
        },
        "deprecated": false,
        "signature_type": "Function"
    },
    {
        "signature_version": "v1",
        "target": {
            "function": "hfsplus_create_attributes_file",
            "file": "fs/hfsplus/xattr.c"
        },
        "id": "CVE-2025-38712-9ba19763",
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@03cd1db1494cf930e2fa042c9c13e32bffdb4eba",
        "digest": {
            "function_hash": "129993581455223314666122366169433619650",
            "length": 2749.0
        },
        "deprecated": false,
        "signature_type": "Function"
    },
    {
        "signature_version": "v1",
        "target": {
            "file": "fs/hfsplus/xattr.c"
        },
        "id": "CVE-2025-38712-a524d6cd",
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@1bb8da27ff15e346d4bc9e248e819c9a88ebf9d6",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "337637008272987461766692467184874204434",
                "164857410119348318271743488210841190392",
                "299857197256906545469360148947087129095",
                "220626602264411295320622016003642110814"
            ]
        },
        "deprecated": false,
        "signature_type": "Line"
    },
    {
        "signature_version": "v1",
        "target": {
            "file": "fs/hfsplus/xattr.c"
        },
        "id": "CVE-2025-38712-a5e1da77",
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@9046566fa692f88954dac8c510f37ee17a15fdb7",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "337637008272987461766692467184874204434",
                "164857410119348318271743488210841190392",
                "299857197256906545469360148947087129095",
                "220626602264411295320622016003642110814"
            ]
        },
        "deprecated": false,
        "signature_type": "Line"
    },
    {
        "signature_version": "v1",
        "target": {
            "function": "hfsplus_create_attributes_file",
            "file": "fs/hfsplus/xattr.c"
        },
        "id": "CVE-2025-38712-c05e4a97",
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@b3359392b75395a31af739a761f48f4041148226",
        "digest": {
            "function_hash": "129993581455223314666122366169433619650",
            "length": 2749.0
        },
        "deprecated": false,
        "signature_type": "Function"
    },
    {
        "signature_version": "v1",
        "target": {
            "file": "fs/hfsplus/xattr.c"
        },
        "id": "CVE-2025-38712-d5ca2cb2",
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@b3359392b75395a31af739a761f48f4041148226",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "337637008272987461766692467184874204434",
                "164857410119348318271743488210841190392",
                "299857197256906545469360148947087129095",
                "220626602264411295320622016003642110814"
            ]
        },
        "deprecated": false,
        "signature_type": "Line"
    },
    {
        "signature_version": "v1",
        "target": {
            "file": "fs/hfsplus/xattr.c"
        },
        "id": "CVE-2025-38712-efe26080",
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@dee5c668ad71ddbcb4b48d95e8a4f371314ad41d",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "337637008272987461766692467184874204434",
                "164857410119348318271743488210841190392",
                "299857197256906545469360148947087129095",
                "220626602264411295320622016003642110814"
            ]
        },
        "deprecated": false,
        "signature_type": "Line"
    }
]