Junglewise Threat Intelligence

CVE-2026-64360: Linux Kernel uninitialized memory access in HFS hfs_bnode_read

CVE-2026-64360 · Severity: info · CVSS 0 · Published 2026-07-25

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's HFS and HFS+ file system drivers, which are used to read and write disks formatted for Apple computers. Under certain conditions, the system could read uninitialized memory from the computer's stack, potentially leading to unpredictable system behavior or the exposure of small amounts of sensitive kernel data. This issue has been resolved in recent kernel updates by ensuring data buffers are properly cleared before use.

Technical details

A vulnerability in the Linux kernel's HFS and HFS+ filesystem drivers (fs/hfs/bnode.c and fs/hfsplus/bnode.c) allowed for uninitialized memory access. The function hfs_bnode_read() could return early if is_bnode_offset_valid() failed or if the requested length was corrected to zero, leaving the caller's stack-allocated buffer in an uninitialized state. Callers like hfs_bnode_read_u16() and hfs_bnode_read_u8() would then use these uninitialized values, as detected by KernelMemorySanitizer (KMSAN). The fix involves zero-initializing the buffer with memset() at the start of hfs_bnode_read() to ensure deterministic behavior.

Affected products

  • Linux Linux Kernel 5.10.241 to 5.10.261; 6.1.x; 6.6.x; 6.10.x

Timeline

  • 2026-05-05: other: Vulnerability fixed in source code by Tristan Madani
  • 2026-07-25: disclosed: CVE published

References

Related threats