Description
In the Linux kernel, the following vulnerability has been resolved:

hfsplus: validate thread record before delete key rebuild

hfsplus_delete_cat() is called with str == NULL when the last open
reference to an unlinked HFS+ hardlink backing inode is closed. In that
case, the function finds the catalog thread by CNID and rebuilds the
catalog key from thread.nodeName.

That reconstruction path reads thread.nodeName.length directly from the
catalog B-tree into fd.search_key and then copies length * 2 bytes into
fd.search_key->cat.name.unicode. It does not first check that the found
record is a thread record or that its size matches the thread name.

A corrupted image can therefore provide an oversized thread name length
and make hfs_bnode_read() write past the catalog search-key allocation.

Read the CNID record through hfsplus_brec_read_cat(), which bounds the
record read to sizeof(hfsplus_cat_entry) and verifies that a thread
record's size exactly matches nodeName.length. Together, these checks
ensure an accepted thread name fits HFSPLUS_MAX_STRLEN. Reject non-thread
records before building the delete key from the validated thread name.

Share the thread-record-type helper between hfsplus_find_cat() and
hfsplus_delete_cat().
Published: 2026-09-17
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Kernel Buffer Overflow
Action: Immediate Patch
AI Analysis

Impact

The kernel flaw appears when hfsplus_delete_cat() processes a corrupted HFS+ catalog entry. It reads the thread name length directly from a B-tree record, then copies that many bytes into a search key structure without first verifying the record is a thread record or that its size matches nodeName.length. This unchecked copy can overrun the buffer and corrupt kernel memory, potentially leading to arbitrary kernel code execution or a system crash.

Affected Systems

All Linux kernels that include HFS+ file system support are potentially affected until the upstream patch that validates the thread record before rebuilding the delete key is applied. The vendor list indicates generic Linux kernels (Linux:Linux) and the CPE points to the Linux kernel; there are no distribution‑specific version restrictions in the data, so the issue applies broadly to any kernel with HFS+ enabled.

Risk and Exploitability

The vulnerability has a CVSS base score of 7.8, indicating high severity, while the EPSS score of less than 1 % suggests a low probability of exploitation in the wild. The flaw requires the kernel to read a malformed or malicious HFS+ image—such as by mounting a corrupted partition—which limits the attack surface to local or privileged actors. Attackers could achieve local privilege escalation or denial‑of‑service by triggering the buffer overflow; remote exploitation would likely need a prior compromise that allows an adversary to present a corrupted HFS+ image to the target.

Generated by OpenCVE AI on September 20, 2026 at 00:14 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that includes the upstream patch for thread‑record validation before delete key rebuild.
  • If a newer kernel is not available, disable HFS+ support by removing the module with modprobe -r hfsplus or preventing the kernel from mounting HFS+ volumes.
  • If you maintain a custom kernel, apply the upstream patch that bounds the thread record read and validates the record type (e.g., apply commit 33cda0036bc683fc888c20b04a5fc030e3e8413b).
  • Monitor system logs for HFS+‑related errors and avoid mounting untrusted HFS+ images until a patch is applied.

Generated by OpenCVE AI on September 20, 2026 at 00:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sun, 20 Sep 2026 00:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119

Sat, 19 Sep 2026 17:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-122

Sat, 19 Sep 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-122

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: hfsplus: validate thread record before delete key rebuild hfsplus_delete_cat() is called with str == NULL when the last open reference to an unlinked HFS+ hardlink backing inode is closed. In that case, the function finds the catalog thread by CNID and rebuilds the catalog key from thread.nodeName. That reconstruction path reads thread.nodeName.length directly from the catalog B-tree into fd.search_key and then copies length * 2 bytes into fd.search_key->cat.name.unicode. It does not first check that the found record is a thread record or that its size matches the thread name. A corrupted image can therefore provide an oversized thread name length and make hfs_bnode_read() write past the catalog search-key allocation. Read the CNID record through hfsplus_brec_read_cat(), which bounds the record read to sizeof(hfsplus_cat_entry) and verifies that a thread record's size exactly matches nodeName.length. Together, these checks ensure an accepted thread name fits HFSPLUS_MAX_STRLEN. Reject non-thread records before building the delete key from the validated thread name. Share the thread-record-type helper between hfsplus_find_cat() and hfsplus_delete_cat().
Title hfsplus: validate thread record before delete key rebuild
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:55:54.948Z

Reserved: 2026-09-17T16:02:15.084Z

Link: CVE-2026-93095

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:18:03.557

Modified: 2026-09-18T18:18:20.477

Link: CVE-2026-93095

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T00:15:06Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer