PT-2026-64582 · Linux · Linux
CVE-2026-64361
·
Published
2026-07-25
·
Updated
2026-07-25
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
In the Linux kernel, the following vulnerability has been resolved:
hfs/hfsplus: fix u32 overflow in check and correct requested length
check and correct requested length() compares (off + len) against
node size using u32 arithmetic. When the caller passes a large len
value (e.g. from an underflowed subtraction in hfs brec remove()),
off + len can wrap past 2^32 and produce a small result, causing the
bounds check to pass when it should fail.
For example, with off=14 and len=0xFFFFFFF2 (underflowed from
data off - keyoffset - size in hfs brec remove), off + len wraps to 6,
which is less than a typical node size of 512, so the check passes and
the subsequent memmove reads ~4GB past the node buffer.
Fix this by widening the addition to u64 before comparing against
node size. This prevents the u32 wrap while keeping the logic
straightforward.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux