CVE-2026-93095
CVE CVE-2026-93095EUVD EUVD-2026-82203Published 2026-09-17T16:11:09.000ZLast changed 2026-09-18T17:55:54.000ZCVSS 7.8
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: hfsplus: validate thread record before delete key rebuild hfsplus_delete_cat() is called with str == NULL when the last open reference to an unlinked HFS+ hardlink backing inode is closed. In that case, the function finds the catalog thread by CNID and rebuilds the catalog key from thread.nodeName. That reconstruction path reads thread.nodeName.length directly from the catalog B-tree into fd.search_key and then copies length * 2 bytes into fd.search_key->cat.name.unicode. It does not first check that the found record is a thread record or that its size matches the thread name. A corrupted image can therefore provide an oversized thread name length and make hfs_bnode_read() write past the catalog search-key allocation. Read the CNID record through hfsplus_brec_read_cat(), which bounds the record read to sizeof(hfsplus_cat_entry) and verifies that a thread record's size exactly matches nodeName.length. Together, these checks ensure an accepted thread name fits HFSPLUS_MAX_STRLEN. Reject non-thread records before building the delete key from the validated thread name. Share the thread-record-type helper between hfsplus_find_cat() and hfsplus_delete_cat().
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux patch: 6.12.110; patch: 7.2.6; 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <b9729c51a8b67f8b20b8a8cf395da4be63a0c15b; patch: 5.10.270; 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <e2ea5cac61acfc11dad22f1d2d4bc71d56c52a20; 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <af48abc1b00d865c3f4c4d76b901c44115cb7162; 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <e31985c67ba00a59d9b1340af473c1dbe6c87856; 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <33cda0036bc683fc888c20b04a5fc030e3e8413b; 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <e20f3b749ad241df77ec1c3e13a9c22209aa1eb3; 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <473ea7aa35615829f0de7a71e8691d69dc24e328; patch: 6.6.157; patch: 5.15.221; patch: 7.3-rc1; patch: 6.18.52; patch: 0; patch: 6.1.188; 2.6.12; 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <7898beee166c1145c0bca364d687b8437435bf1a
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.