Junglewise Threat Intelligence

CVE-2026-80656: Linux kernel HFS+ btree node size validation bypass

CVE-2026-80656 · Severity: high · CVSS 7.8 · Published 2026-08-28

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's HFS+ filesystem driver failed to properly validate B-tree node sizes during filesystem mounting, allowing a maliciously crafted HFS+ disk image to trigger uninitialized memory bugs. An attacker could craft a corrupt HFS+ image with invalid node sizes to crash the system or potentially execute code when a user mounts the filesystem.

Technical details

This vulnerability is an input validation flaw in the HFS+ filesystem B-tree parsing code (fs/hfsplus/btree.c). When mounting an HFS+ filesystem, the code reads a node_size value from the disk metadata without first validating that it falls within the valid range (512–32,768 bytes, power of two). A corrupted or malicious filesystem image specifying an invalid node_size (e.g., 1) causes hfs_bnode_read_u16() to compute an excessively large offset, leading to reads from uninitialized memory (KMSAN: uninit-value bug). The vulnerability is triggered during mount (filesystem parsing), requiring only local access to a malicious image file. The fix adds a sanity check: if node_size is outside [512, 32768] or is not a power of two, the mount operation fails gracefully.

Affected products

  • Linux Linux kernel All versions prior to fix (commit 3f95e2661574ff13f099dd13456751933c280628)

Timeline

  • 2026-08-28: disclosed
  • 2026-04-27: patched: Upstream fix merged April 27, 2026; stable backports from July 24, 2026

References

Related threats