CVE-2026-64361: Linux Kernel
High severity, CVSS 7.8. EPSS: 0.1% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: hfs/hfsplus: fix u32 overflow in check_and_correct_requested_length check_and_correct_requested_length() compares (off + len) against node_size using u32 arithmetic. When the caller passes a large len value (e.g. from an underflowed subtraction in hfs_brec_remove()), off + len can wrap past 2^32 and produce a small result, causing the bounds check to pass when it should fail. For example, with off=14 and len=0xFFFFFFF2 (underflowed from data_off - keyoffset - size in hfs_brec_remove), off + len wraps to 6, which is less than a typical node_size of 512, so the check passes and the subsequent memmove reads ~4GB past the node buffer. Fix this by widening the addition to u64 before comparing against node_size. This prevents the u32 wrap while keeping the logic straightforward.
Affected products
- Linux Linux Kernel: from 5.4.297, before 5.5 (fixed in 5.5); from 5.10.241, before 5.10.261 (fixed in 5.10.261); from 5.15.190, before 5.15.212 (fixed in 5.15.212); from 6.1.149, before 6.1.178 (fixed in 6.1.178); from 6.6.103, before 6.6.145 (fixed in 6.6.145); from 6.12.43, before 6.12.97 (fixed in 6.12.97); …
Published 2026-07-25. Last modified 2026-09-04.