Junglewise Threat Intelligence

CVE-2026-74414: Linux kernel hfsplus null pointer dereference in setxattr

CVE-2026-74414 · Severity: info · Published 2026-08-15

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The HFS+ filesystem driver in the Linux kernel contains a null pointer dereference vulnerability triggered when setting extended file attributes (setxattr) if the attributes file was not loaded during filesystem mount. This can cause a kernel crash, leading to denial of service on systems using HFS+ filesystems.

Technical details

The vulnerability is a null pointer dereference in the hfsplus_setxattr function (fs/hfsplus/xattr.c:555) that occurs when the attributes file is not initialized during filesystem mount. The root cause is a duplicate call to hfsplus_mark_inode_dirty() in the attribute tree initialization code; the first call attempts to mark an uninitialized inode as dirty, dereferencing a null pointer. The attack vector is local—an unprivileged user can trigger the crash by calling setxattr on a file in an HFS+ filesystem that lacks a properly initialized attributes file. The fix removes the redundant first hfsplus_mark_inode_dirty() call. A patch is available in the Linux kernel stable tree.

Affected products

  • Linux Linux Kernel all versions prior to fix commit 7a41fd2b32e5908f19a68732008d581c167279dd

Timeline

  • 2026-04-16: disclosed: Bug reported by Syzbot
  • 2026-04-27: patched: Patch committed to Linux kernel mainline

References

Related threats