CVE-2026-74414
Gravedad:
Pendiente de análisis
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
15/08/2026
Última modificación:
15/08/2026
Descripción
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
hfsplus: Remove the duplicate attr inode dirty marking action<br />
<br />
Syzbot reported a null-ptr-deref in [1].<br />
If the attributes file is not loaded during system mount, a trigger<br />
occurs [1] when setxattr is executed in userspace.<br />
<br />
Remove the first mark attr inode dirty operation.<br />
<br />
[1]<br />
KASAN: null-ptr-deref in range [0x0000000000000008-0x000000000000000f]<br />
Call Trace:<br />
hfsplus_setxattr+0x124/0x340 fs/hfsplus/xattr.c:555<br />
hfsplus_trusted_setxattr+0x40/0x60 fs/hfsplus/xattr_trusted.c:30<br />
__vfs_setxattr+0x43c/0x480 fs/xattr.c:218<br />
__vfs_setxattr_noperm+0x12d/0x660 fs/xattr.c:252<br />
vfs_setxattr+0x163/0x360 fs/xattr.c:339<br />
do_setxattr fs/xattr.c:654 [inline]



