PatchSiren cyber security CVE debrief
CVE-2026-64360 Linux CVE debrief
A vulnerability in the Linux kernel's hfs_bnode_read function can lead to uninitialized buffer exposure. This issue arises when the function returns early without writing to the output buffer, potentially causing KMSAN uninit-value reports. The vulnerability has been resolved through a series of patches that ensure all callers in both hfs and hfsplus get a deterministic zero value. Linux kernel maintainers and users should be aware of this vulnerability and take necessary actions to ensure system security.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-25
- Original CVE updated
- 2026-09-04
- Advisory published
- 2026-07-25
- Advisory updated
- 2026-09-04
Who should care
Linux kernel maintainers, users, and administrators, especially those using affected versions, should be aware of this vulnerability and take necessary actions to ensure system security. This includes applying patches, reviewing system logs, and verifying system security to prevent potential KMSAN uninit-value reports.
Why it matters
This vulnerability in the Linux kernel's hfs_bnode_read function can lead to uninitialized buffer exposure, potentially causing KMSAN uninit-value reports. Linux kernel maintainers and users, especially those using affected versions, should apply patches and ensure system security.
- Potential exposure of uninitialized buffer contents
- KMSAN uninit-value reports may occur
- Verification of patch application and system security is necessary
Technical summary
The hfs_bnode_read function in the Linux kernel can return early without writing to the output buffer, potentially causing KMSAN uninit-value reports. The vulnerability has been resolved through patches that zero-initialize the buffer at the start of the function. This fix ensures all callers in both hfs and hfsplus get a deterministic zero value. The vulnerability affects Linux kernel versions and has been addressed through official patches provided by the Linux kernel maintainers. Users and maintainers should apply these patches and review system security to prevent potential exposure.
Defensive priority
Medium priority for Linux kernel maintainers and users, especially those using affected versions, to apply patches and ensure system security.
Recommended defensive actions
- Apply patches provided by the Linux kernel maintainers to fix the vulnerability
- Review and update affected Linux kernel versions to ensure system security
- Monitor system logs for potential KMSAN uninit-value reports
- Verify patch application and system security
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record and NVD vulnerability detail page provide information on the vulnerability, its impact, and available patches. Multiple source references are available, including several patch links. The vulnerability was resolved by zeroing the buffer at the start of hfs_bnode_read() before any validation checks. This ensures all callers get a deterministic zero value regardless of which early-return path is taken. The fix prevents potential KMSAN uninit-value reports by ensuring the buffer is initialized before use.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-64360 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-64360
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-64360 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-64360
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/0b189b2204f1a2612dc68f8d139fb5b80539e710
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/16ca053c2be5f4f3044dccf7fc19237dc820d394
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/34684a04777358b2b40ac729e54c8e45359e46b3
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/8f72fd25a57a457866350359ddd27a43caa62c95
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/d2afc7ecee476f9251dd87444f7fb6a424410922
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/d5b45bad75cd2730b8452aed4d3b20a2b2a12576
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/d67aadee19ffdf3cc8520c5a4f4d5b2916d30baf
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/f3461b84a4865d9b5e70fbb71da72ae044a3bcd2
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.