Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-74414

Gravedad:
Pendiente de análisis
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
15/08/2026
Última modificación:
15/08/2026

Descripción

*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> hfsplus: Remove the duplicate attr inode dirty marking action<br /> <br /> Syzbot reported a null-ptr-deref in [1].<br /> If the attributes file is not loaded during system mount, a trigger<br /> occurs [1] when setxattr is executed in userspace.<br /> <br /> Remove the first mark attr inode dirty operation.<br /> <br /> [1]<br /> KASAN: null-ptr-deref in range [0x0000000000000008-0x000000000000000f]<br /> Call Trace:<br /> hfsplus_setxattr+0x124/0x340 fs/hfsplus/xattr.c:555<br /> hfsplus_trusted_setxattr+0x40/0x60 fs/hfsplus/xattr_trusted.c:30<br /> __vfs_setxattr+0x43c/0x480 fs/xattr.c:218<br /> __vfs_setxattr_noperm+0x12d/0x660 fs/xattr.c:252<br /> vfs_setxattr+0x163/0x360 fs/xattr.c:339<br /> do_setxattr fs/xattr.c:654 [inline]

Impacto