Home

Description

In the Linux kernel, the following vulnerability has been resolved: hfs: Replace BUG_ON with error handling for CNID count checks In a06ec283e125 next_id, folder_count, and file_count in the super block info were expanded to 64 bits, and BUG_ONs were added to detect overflow. This triggered an error reported by syzbot: if the MDB is corrupted, the BUG_ON is triggered. This patch replaces this mechanism with proper error handling and resolves the syzbot reported bug. Singed-off-by: Jori Koolstra <jkoolstra@xs4all.nl>

PUBLISHED Reserved 2026-05-01 | Published 2026-05-06 | Updated 2026-05-07 | Assigner Linux

Product status

Default status
unaffected

a06ec283e125e334155fe13005c76c9f484ce759 (git) before b6536c1ced315fa645576d3a39c6e07f2a472962
affected

a06ec283e125e334155fe13005c76c9f484ce759 (git) before b226804532a875c10276168dc55ce752944096bd
affected

Default status
affected

6.18
affected

Any version before 6.18
unaffected

6.19.6 (semver)
unaffected

7.0 (original_commit_for_fix)
unaffected

References

git.kernel.org/...c/b6536c1ced315fa645576d3a39c6e07f2a472962

git.kernel.org/...c/b226804532a875c10276168dc55ce752944096bd

cve.org (CVE-2026-43228)

nvd.nist.gov (CVE-2026-43228)

Download JSON