{"api_version":"1","generated_at":"2026-07-28T12:20:23+00:00","cve":"CVE-2026-64361","urls":{"html":"https://cve.report/CVE-2026-64361","api":"https://cve.report/api/cve/CVE-2026-64361.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-64361","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-64361"},"summary":{"title":"hfs/hfsplus: fix u32 overflow in check_and_correct_requested_length","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nhfs/hfsplus: fix u32 overflow in check_and_correct_requested_length\n\ncheck_and_correct_requested_length() compares (off + len) against\nnode_size using u32 arithmetic.  When the caller passes a large len\nvalue (e.g. from an underflowed subtraction in hfs_brec_remove()),\noff + len can wrap past 2^32 and produce a small result, causing the\nbounds check to pass when it should fail.\n\nFor example, with off=14 and len=0xFFFFFFF2 (underflowed from\ndata_off - keyoffset - size in hfs_brec_remove), off + len wraps to 6,\nwhich is less than a typical node_size of 512, so the check passes and\nthe subsequent memmove reads ~4GB past the node buffer.\n\nFix this by widening the addition to u64 before comparing against\nnode_size.  This prevents the u32 wrap while keeping the logic\nstraightforward.","state":"PUBLISHED","assigner":"Linux","published_at":"2026-07-25 10:17:18","updated_at":"2026-07-27 05:16:43"},"problem_types":[],"metrics":[{"version":"3.1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","score":"7.8","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"7.8","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","data":{"baseScore":7.8,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"}}],"references":[{"url":"https://git.kernel.org/stable/c/607217f7ad419b53926f71e3f75001813bbc08ad","name":"https://git.kernel.org/stable/c/607217f7ad419b53926f71e3f75001813bbc08ad","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/b6a481642ea1977be2f84dc08c5affd742c177e7","name":"https://git.kernel.org/stable/c/b6a481642ea1977be2f84dc08c5affd742c177e7","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/966cb76fb2857a4242cab6ea2ea17acf818a3da7","name":"https://git.kernel.org/stable/c/966cb76fb2857a4242cab6ea2ea17acf818a3da7","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/c8dd112173c02adf539fe2ad34a45f5e0068780d","name":"https://git.kernel.org/stable/c/c8dd112173c02adf539fe2ad34a45f5e0068780d","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/fc9d1447ca3cdc78d2e4ace1ce1f3a7c77ca08b1","name":"https://git.kernel.org/stable/c/fc9d1447ca3cdc78d2e4ace1ce1f3a7c77ca08b1","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/7399c3baee7bb622a92f0b895cd4d3009a693f2b","name":"https://git.kernel.org/stable/c/7399c3baee7bb622a92f0b895cd4d3009a693f2b","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/671c3fcc2ad31c1311ea6414382a2d95104ae1b9","name":"https://git.kernel.org/stable/c/671c3fcc2ad31c1311ea6414382a2d95104ae1b9","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/c25d3c931a63e762fcaa9cb125b901c53b62403f","name":"https://git.kernel.org/stable/c/c25d3c931a63e762fcaa9cb125b901c53b62403f","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-64361","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-64361","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 67ecc81f6492275c9c54280532f558483c99c90e c8dd112173c02adf539fe2ad34a45f5e0068780d git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected a1a60e79502279f996e55052f50cc14919020475 fc9d1447ca3cdc78d2e4ace1ce1f3a7c77ca08b1 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected fe2891a9c43ab87d1a210d61e6438ca6936e2f62 671c3fcc2ad31c1311ea6414382a2d95104ae1b9 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 384a66b89f9540a9a8cb0f48807697dfabaece4c b6a481642ea1977be2f84dc08c5affd742c177e7 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected efc095b35b23297e419c2ab4fc1ed1a8f0781a29 7399c3baee7bb622a92f0b895cd4d3009a693f2b git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected a431930c9bac518bf99d6b1da526a7f37ddee8d8 607217f7ad419b53926f71e3f75001813bbc08ad git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected a431930c9bac518bf99d6b1da526a7f37ddee8d8 c25d3c931a63e762fcaa9cb125b901c53b62403f git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected a431930c9bac518bf99d6b1da526a7f37ddee8d8 966cb76fb2857a4242cab6ea2ea17acf818a3da7 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected e7d2dc2421e821e4045775e6dc226378328de6f6 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected fc7f732984ec91f30be3e574e0644066d07f2b78 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected eec522fd0d28106b14a59ab2d658605febe4a3bb git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 5.10.241 5.10.261 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 5.15.190 5.15.212 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 6.1.149 6.1.178 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 6.6.103 6.6.145 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 6.12.43 6.12.97 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 5.4.297 5.5 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 6.15.11 6.16 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 6.16.2 6.17 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 6.17","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.17 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 5.10.261 5.10.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 5.15.212 5.15.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.1.178 6.1.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.6.145 6.6.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.12.97 6.12.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.18.40 6.18.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.1.4 7.1.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.2-rc1 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"64361","cve":"CVE-2026-64361","epss":"0.001290000","percentile":"0.029510000","score_date":"2026-07-27","updated_at":"2026-07-28 00:07:43"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["fs/hfs/bnode.c","fs/hfsplus/hfsplus_fs.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"c8dd112173c02adf539fe2ad34a45f5e0068780d","status":"affected","version":"67ecc81f6492275c9c54280532f558483c99c90e","versionType":"git"},{"lessThan":"fc9d1447ca3cdc78d2e4ace1ce1f3a7c77ca08b1","status":"affected","version":"a1a60e79502279f996e55052f50cc14919020475","versionType":"git"},{"lessThan":"671c3fcc2ad31c1311ea6414382a2d95104ae1b9","status":"affected","version":"fe2891a9c43ab87d1a210d61e6438ca6936e2f62","versionType":"git"},{"lessThan":"b6a481642ea1977be2f84dc08c5affd742c177e7","status":"affected","version":"384a66b89f9540a9a8cb0f48807697dfabaece4c","versionType":"git"},{"lessThan":"7399c3baee7bb622a92f0b895cd4d3009a693f2b","status":"affected","version":"efc095b35b23297e419c2ab4fc1ed1a8f0781a29","versionType":"git"},{"lessThan":"607217f7ad419b53926f71e3f75001813bbc08ad","status":"affected","version":"a431930c9bac518bf99d6b1da526a7f37ddee8d8","versionType":"git"},{"lessThan":"c25d3c931a63e762fcaa9cb125b901c53b62403f","status":"affected","version":"a431930c9bac518bf99d6b1da526a7f37ddee8d8","versionType":"git"},{"lessThan":"966cb76fb2857a4242cab6ea2ea17acf818a3da7","status":"affected","version":"a431930c9bac518bf99d6b1da526a7f37ddee8d8","versionType":"git"},{"status":"affected","version":"e7d2dc2421e821e4045775e6dc226378328de6f6","versionType":"git"},{"status":"affected","version":"fc7f732984ec91f30be3e574e0644066d07f2b78","versionType":"git"},{"status":"affected","version":"eec522fd0d28106b14a59ab2d658605febe4a3bb","versionType":"git"},{"lessThan":"5.10.261","status":"affected","version":"5.10.241","versionType":"semver"},{"lessThan":"5.15.212","status":"affected","version":"5.15.190","versionType":"semver"},{"lessThan":"6.1.178","status":"affected","version":"6.1.149","versionType":"semver"},{"lessThan":"6.6.145","status":"affected","version":"6.6.103","versionType":"semver"},{"lessThan":"6.12.97","status":"affected","version":"6.12.43","versionType":"semver"},{"lessThan":"5.5","status":"affected","version":"5.4.297","versionType":"semver"},{"lessThan":"6.16","status":"affected","version":"6.15.11","versionType":"semver"},{"lessThan":"6.17","status":"affected","version":"6.16.2","versionType":"semver"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["fs/hfs/bnode.c","fs/hfsplus/hfsplus_fs.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"6.17"},{"lessThan":"6.17","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"5.10.*","status":"unaffected","version":"5.10.261","versionType":"semver"},{"lessThanOrEqual":"5.15.*","status":"unaffected","version":"5.15.212","versionType":"semver"},{"lessThanOrEqual":"6.1.*","status":"unaffected","version":"6.1.178","versionType":"semver"},{"lessThanOrEqual":"6.6.*","status":"unaffected","version":"6.6.145","versionType":"semver"},{"lessThanOrEqual":"6.12.*","status":"unaffected","version":"6.12.97","versionType":"semver"},{"lessThanOrEqual":"6.18.*","status":"unaffected","version":"6.18.40","versionType":"semver"},{"lessThanOrEqual":"7.1.*","status":"unaffected","version":"7.1.4","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.2-rc1","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"5.10.261","versionStartIncluding":"5.10.241","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"5.15.212","versionStartIncluding":"5.15.190","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.1.178","versionStartIncluding":"6.1.149","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.6.145","versionStartIncluding":"6.6.103","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.12.97","versionStartIncluding":"6.12.43","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.18.40","versionStartIncluding":"6.17","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.1.4","versionStartIncluding":"6.17","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2-rc1","versionStartIncluding":"6.17","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.4.297","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.15.11","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.16.2","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nhfs/hfsplus: fix u32 overflow in check_and_correct_requested_length\n\ncheck_and_correct_requested_length() compares (off + len) against\nnode_size using u32 arithmetic.  When the caller passes a large len\nvalue (e.g. from an underflowed subtraction in hfs_brec_remove()),\noff + len can wrap past 2^32 and produce a small result, causing the\nbounds check to pass when it should fail.\n\nFor example, with off=14 and len=0xFFFFFFF2 (underflowed from\ndata_off - keyoffset - size in hfs_brec_remove), off + len wraps to 6,\nwhich is less than a typical node_size of 512, so the check passes and\nthe subsequent memmove reads ~4GB past the node buffer.\n\nFix this by widening the addition to u64 before comparing against\nnode_size.  This prevents the u32 wrap while keeping the logic\nstraightforward."}],"metrics":[{"cvssV3_1":{"baseScore":7.8,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"}}],"providerMetadata":{"dateUpdated":"2026-07-27T04:59:55.178Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/c8dd112173c02adf539fe2ad34a45f5e0068780d"},{"url":"https://git.kernel.org/stable/c/fc9d1447ca3cdc78d2e4ace1ce1f3a7c77ca08b1"},{"url":"https://git.kernel.org/stable/c/671c3fcc2ad31c1311ea6414382a2d95104ae1b9"},{"url":"https://git.kernel.org/stable/c/b6a481642ea1977be2f84dc08c5affd742c177e7"},{"url":"https://git.kernel.org/stable/c/7399c3baee7bb622a92f0b895cd4d3009a693f2b"},{"url":"https://git.kernel.org/stable/c/607217f7ad419b53926f71e3f75001813bbc08ad"},{"url":"https://git.kernel.org/stable/c/c25d3c931a63e762fcaa9cb125b901c53b62403f"},{"url":"https://git.kernel.org/stable/c/966cb76fb2857a4242cab6ea2ea17acf818a3da7"}],"title":"hfs/hfsplus: fix u32 overflow in check_and_correct_requested_length","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-64361","datePublished":"2026-07-25T08:50:17.345Z","dateReserved":"2026-07-19T15:36:31.783Z","dateUpdated":"2026-07-27T04:59:55.178Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-07-25 10:17:18","lastModifiedDate":"2026-07-27 05:16:43","problem_types":[],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"64361","Ordinal":"1","Title":"hfs/hfsplus: fix u32 overflow in check_and_correct_requested_len","CVE":"CVE-2026-64361","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"64361","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\nhfs/hfsplus: fix u32 overflow in check_and_correct_requested_length\n\ncheck_and_correct_requested_length() compares (off + len) against\nnode_size using u32 arithmetic.  When the caller passes a large len\nvalue (e.g. from an underflowed subtraction in hfs_brec_remove()),\noff + len can wrap past 2^32 and produce a small result, causing the\nbounds check to pass when it should fail.\n\nFor example, with off=14 and len=0xFFFFFFF2 (underflowed from\ndata_off - keyoffset - size in hfs_brec_remove), off + len wraps to 6,\nwhich is less than a typical node_size of 512, so the check passes and\nthe subsequent memmove reads ~4GB past the node buffer.\n\nFix this by widening the addition to u64 before comparing against\nnode_size.  This prevents the u32 wrap while keeping the logic\nstraightforward.","Type":"Description","Title":"hfs/hfsplus: fix u32 overflow in check_and_correct_requested_len"}]}}}