Executive brief
The HFS+ filesystem driver in the Linux kernel contains a null pointer dereference vulnerability triggered when setting extended file attributes (setxattr) if the attributes file was not loaded during filesystem mount. This can cause a kernel crash, leading to denial of service on systems using HFS+ filesystems.
Technical details
The vulnerability is a null pointer dereference in the hfsplus_setxattr function (fs/hfsplus/xattr.c:555) that occurs when the attributes file is not initialized during filesystem mount. The root cause is a duplicate call to hfsplus_mark_inode_dirty() in the attribute tree initialization code; the first call attempts to mark an uninitialized inode as dirty, dereferencing a null pointer. The attack vector is local—an unprivileged user can trigger the crash by calling setxattr on a file in an HFS+ filesystem that lacks a properly initialized attributes file. The fix removes the redundant first hfsplus_mark_inode_dirty() call. A patch is available in the Linux kernel stable tree.
Affected products
- Linux Linux Kernel all versions prior to fix commit 7a41fd2b32e5908f19a68732008d581c167279dd
Timeline
- 2026-04-16: disclosed: Bug reported by Syzbot
- 2026-04-27: patched: Patch committed to Linux kernel mainline