PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-64360 Linux CVE debrief

A vulnerability in the Linux kernel's hfs_bnode_read function can lead to uninitialized buffer exposure. This issue arises when the function returns early without writing to the output buffer, potentially causing KMSAN uninit-value reports. The vulnerability has been resolved through a series of patches that ensure all callers in both hfs and hfsplus get a deterministic zero value. Linux kernel maintainers and users should be aware of this vulnerability and take necessary actions to ensure system security.

Vendor
Linux
Product
Unknown
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-25
Original CVE updated
2026-09-04
Advisory published
2026-07-25
Advisory updated
2026-09-04

Who should care

Linux kernel maintainers, users, and administrators, especially those using affected versions, should be aware of this vulnerability and take necessary actions to ensure system security. This includes applying patches, reviewing system logs, and verifying system security to prevent potential KMSAN uninit-value reports.

Why it matters

This vulnerability in the Linux kernel's hfs_bnode_read function can lead to uninitialized buffer exposure, potentially causing KMSAN uninit-value reports. Linux kernel maintainers and users, especially those using affected versions, should apply patches and ensure system security.

  • Potential exposure of uninitialized buffer contents
  • KMSAN uninit-value reports may occur
  • Verification of patch application and system security is necessary

Technical summary

The hfs_bnode_read function in the Linux kernel can return early without writing to the output buffer, potentially causing KMSAN uninit-value reports. The vulnerability has been resolved through patches that zero-initialize the buffer at the start of the function. This fix ensures all callers in both hfs and hfsplus get a deterministic zero value. The vulnerability affects Linux kernel versions and has been addressed through official patches provided by the Linux kernel maintainers. Users and maintainers should apply these patches and review system security to prevent potential exposure.

Defensive priority

Medium priority for Linux kernel maintainers and users, especially those using affected versions, to apply patches and ensure system security.

Recommended defensive actions

  • Apply patches provided by the Linux kernel maintainers to fix the vulnerability
  • Review and update affected Linux kernel versions to ensure system security
  • Monitor system logs for potential KMSAN uninit-value reports
  • Verify patch application and system security
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record and NVD vulnerability detail page provide information on the vulnerability, its impact, and available patches. Multiple source references are available, including several patch links. The vulnerability was resolved by zeroing the buffer at the start of hfs_bnode_read() before any validation checks. This ensures all callers get a deterministic zero value regardless of which early-return path is taken. The fix prevents potential KMSAN uninit-value reports by ensuring the buffer is initialized before use.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-64360 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-64360

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-64360 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-64360

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/0b189b2204f1a2612dc68f8d139fb5b80539e710

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/16ca053c2be5f4f3044dccf7fc19237dc820d394

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/34684a04777358b2b40ac729e54c8e45359e46b3

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/8f72fd25a57a457866350359ddd27a43caa62c95

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/d2afc7ecee476f9251dd87444f7fb6a424410922

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/d5b45bad75cd2730b8452aed4d3b20a2b2a12576

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/d67aadee19ffdf3cc8520c5a4f4d5b2916d30baf

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/f3461b84a4865d9b5e70fbb71da72ae044a3bcd2

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.