CVE-2026-64360
N/A
Summary
In the Linux kernel, the following vulnerability has been resolved:
hfs/hfsplus: zero-initialize buffer in hfs_bnode_read
hfs_bnode_read() can return early without writing to the output buffer when is_bnode_offset_valid() fails or when check_and_correct_requested_ length() corrects the length to zero. Callers such as hfs_bnode_read_ u16() and hfs_bnode_read_u8() pass stack-allocated buffers and use the result unconditionally, leading to KMSAN uninit-value reports.
Rather than initializing at each individual call site, zero the buffer at the start of hfs_bnode_read() before any validation checks. This ensures all callers in both hfs and hfsplus get a deterministic zero value regardless of which early-return path is taken.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 67ecc81f6492275c9c54280532f558483c99c90e < 34684a04777358b2b40ac729e54c8e45359e46b3 | affected |
| Linux | Linux | a1a60e79502279f996e55052f50cc14919020475 < 0b189b2204f1a2612dc68f8d139fb5b80539e710 | affected |
| Linux | Linux | fe2891a9c43ab87d1a210d61e6438ca6936e2f62 < 8f72fd25a57a457866350359ddd27a43caa62c95 | affected |
| Linux | Linux | 384a66b89f9540a9a8cb0f48807697dfabaece4c < 16ca053c2be5f4f3044dccf7fc19237dc820d394 | affected |
| Linux | Linux | efc095b35b23297e419c2ab4fc1ed1a8f0781a29 < d2afc7ecee476f9251dd87444f7fb6a424410922 | affected |
| Linux | Linux | a431930c9bac518bf99d6b1da526a7f37ddee8d8 < f3461b84a4865d9b5e70fbb71da72ae044a3bcd2 | affected |
| Linux | Linux | a431930c9bac518bf99d6b1da526a7f37ddee8d8 < d5b45bad75cd2730b8452aed4d3b20a2b2a12576 | affected |
| Linux | Linux | a431930c9bac518bf99d6b1da526a7f37ddee8d8 < d67aadee19ffdf3cc8520c5a4f4d5b2916d30baf | affected |
| Linux | Linux | e7d2dc2421e821e4045775e6dc226378328de6f6 | affected |
| Linux | Linux | fc7f732984ec91f30be3e574e0644066d07f2b78 | affected |
| Linux | Linux | eec522fd0d28106b14a59ab2d658605febe4a3bb | affected |
| Linux | Linux | 5.10.241 < 5.10.261 | affected |
| Linux | Linux | 5.15.190 < 5.15.212 | affected |
| Linux | Linux | 6.1.149 < 6.1.178 | affected |
| Linux | Linux | 6.6.103 < 6.6.145 | affected |
| Linux | Linux | 6.12.43 < 6.12.96 | affected |
| Linux | Linux | 5.4.297 < 5.5 | affected |
| Linux | Linux | 6.15.11 < 6.16 | affected |
| Linux | Linux | 6.16.2 < 6.17 | affected |
| Linux | Linux | 6.17 | affected |
| Linux | Linux | 0 < 6.17 | unaffected |
| Linux | Linux | 5.10.261 <= 5.10.* | unaffected |
| Linux | Linux | 5.15.212 <= 5.15.* | unaffected |
| Linux | Linux | 6.1.178 <= 6.1.* | unaffected |
| Linux | Linux | 6.6.145 <= 6.6.* | unaffected |
| Linux | Linux | 6.12.96 <= 6.12.* | unaffected |
| Linux | Linux | 6.18.39 <= 6.18.* | unaffected |
| Linux | Linux | 7.1.4 <= 7.1.* | unaffected |
| Linux | Linux | 7.2-rc1 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/34684a04777358b2b40ac729e54c8e45359e46b3
- https://git.kernel.org/stable/c/0b189b2204f1a2612dc68f8d139fb5b80539e710
- https://git.kernel.org/stable/c/8f72fd25a57a457866350359ddd27a43caa62c95
- https://git.kernel.org/stable/c/16ca053c2be5f4f3044dccf7fc19237dc820d394
- https://git.kernel.org/stable/c/d2afc7ecee476f9251dd87444f7fb6a424410922
- https://git.kernel.org/stable/c/f3461b84a4865d9b5e70fbb71da72ae044a3bcd2
- https://git.kernel.org/stable/c/d5b45bad75cd2730b8452aed4d3b20a2b2a12576
- https://git.kernel.org/stable/c/d67aadee19ffdf3cc8520c5a4f4d5b2916d30baf
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.