Linux Kernel HFS+ File System Vulnerability - Multiple Versions Affected
CVE-2026-74414

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
15 August 2026

What is CVE-2026-74414?

A vulnerability in the HFS+ file system within the Linux kernel can lead to a null pointer dereference when the attributes file is not loaded during a system mount. This issue occurs specifically when the setxattr function is executed from userspace, highlighting a flaw in the management of attribute inodes. The problem has been addressed by removing the redundant marking of the attribute inode as dirty. This fix is aimed at preventing potential crashes or unexpected behaviors when interacting with the HFS+ file system.

Affected Version(s)

Linux ee8422d00b7cfa028823ebf1f28bf9dea428cac3

Linux ee8422d00b7cfa028823ebf1f28bf9dea428cac3 < 7a41fd2b32e5908f19a68732008d581c167279dd

Linux 7.1

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.