CVE-2025-4003 Details
Description
A vulnerability was found in RefindPlusRepo RefindPlus 0.14.2.AB. It has been classified as problematic. This affects the function InternalApfsTranslateBlock of the file Library/RP_ApfsLib/RP_ApfsIo.c. The manipulation leads to null pointer dereference. It is possible to launch the attack on the local host. The patch is named 4d35125ca689a255647e9033dd60c257d26df7cb. It is recommended to apply a patch to fix this issue.
A null pointer dereference vulnerability has been identified in RefindPlusRepo RefindPlus version 0.14.2.AB. This issue occurs in the 'InternalApfsTranslateBlock' function within the file 'Library/RP_ApfsLib/RP_ApfsIo.c'. The vulnerability arises because the 'InternalApfsTranslateBlock' function can return a NULL value, which is then dereferenced, potentially leading to a crash. This vulnerability can be exploited locally.
Users are advised to update to the latest version of RefindPlus, where this vulnerability has been addressed. The patch is available in the commit '4d35125ca689a255647e9033dd60c257d26df7cb'.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Apr 28, 2025CISA-ADP
Assessed Apr 28, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/RefindPlusRepo/RefindPlus/commit/4d35125ca689a255647e9033dd60c257d26df7cb | [email protected] | Source CodeVendor |
| https://github.com/RefindPlusRepo/RefindPlus/issues/206 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
| https://github.com/RefindPlusRepo/RefindPlus/issues/206#event-16595888967 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
| https://vuldb.com/?ctiid.306339 | [email protected] | Content Wall |
| https://vuldb.com/?id.306339 | [email protected] | AdvisoryRemedy |
| https://vuldb.com/?submit.558123 | [email protected] | ExploitIssue TrackingTechnical Description |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-404 | Improper Resource Shutdown or Release | [email protected] |
| CWE-476 | NULL Pointer Dereference | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| RefindPlus | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 28, 2025 | New CVE Received | [email protected] |
Volerion