CVE-2026-64360

Local kernel-stack disclosure via early buffer return

Published Jul 25, 2026 · Updated Jul 25, 2026

Uninitialized-value use in Linux Kernel HFS/HFS+ handling allows local users to expose residual kernel-stack data through malformed metadata. The hfs_bnode_read function returns before writing its caller-provided buffer when offset validation fails or the corrected length becomes zero, while hfs_bnode_read_u16 and hfs_bnode_read_u8 consume the stack buffer unconditionally. Triggering requires local access to process malformed HFS or HFS+ metadata, and the supported consequence is disclosure of residual stack data rather than code execution or service interruption.

CVSS severity3.3
Low
EPSS probability0.12%
Next 30 days · Sep 16, 2026
Known exploitationUnconfirmed
Based on sourced intelligence
Hinoki checkNot available
Coverage for this vulnerability

See if you're affected

Explore vulnerability checks for your environment with Hinoki.

Book a demo

Summary

What happened

Uninitialized-value use in Linux Kernel HFS/HFS+ handling allows local users to expose residual kernel-stack data through malformed metadata. The hfs_bnode_read function returns before writing its caller-provided buffer when offset validation fails or the corrected length becomes zero, while hfs_bnode_read_u16 and hfs_bnode_read_u8 consume the stack buffer unconditionally. Triggering requires local access to process malformed HFS or HFS+ metadata, and the supported consequence is disclosure of residual stack data rather than code execution or service interruption.

The record

CVE
CVE-2026-64360
Published
Jul 25, 2026
Updated
Jul 25, 2026
Vendor
The Linux Kernel Organization
Product
Linux Kernel
Classifications
Unavailable
Attack vector
local
Privileges
authenticated

Timeline

How it unfolded

  1. Jul 25, 2026CVE publishedPublication date reported by the CVE source.
  2. Jul 25, 2026Record updatedLatest update available in the CVE record.

Exploitability

Present is not the same as exploitable

Compare your product and version with the public record. A matching version still requires validation against your environment.

Is a vulnerable build present?

Compare these published version ranges with your installed build and any vendor patches.

  1. Affected versionversion=384a66b89f9540a9a8cb0f48807697dfabaece4c <16ca053c2be5f4f3044dccf7fc19237dc820d394
  2. Affected versionversion=5.10.241 <5.10.261
  3. Affected versionversion=5.15.190 <5.15.212
  4. Affected versionversion=5.4.297 <5.5
  5. Affected versionversion=6.1.149 <6.1.178
  6. Affected versionversion=6.12.43 <6.12.96
  7. Affected versionversion=6.15.11 <6.16
  8. Affected versionversion=6.16.2 <6.17
  9. Affected versionversion=6.17
  10. Affected versionversion=6.6.103 <6.6.145
  11. Affected versionversion=67ecc81f6492275c9c54280532f558483c99c90e <34684a04777358b2b40ac729e54c8e45359e46b3
  12. Affected versionversion=a1a60e79502279f996e55052f50cc14919020475 <0b189b2204f1a2612dc68f8d139fb5b80539e710
  13. Affected versionversion=a431930c9bac518bf99d6b1da526a7f37ddee8d8 <d5b45bad75cd2730b8452aed4d3b20a2b2a12576
  14. Affected versionversion=a431930c9bac518bf99d6b1da526a7f37ddee8d8 <d67aadee19ffdf3cc8520c5a4f4d5b2916d30baf
  15. Affected versionversion=a431930c9bac518bf99d6b1da526a7f37ddee8d8 <f3461b84a4865d9b5e70fbb71da72ae044a3bcd2
  16. Affected versionversion=e7d2dc2421e821e4045775e6dc226378328de6f6
  17. Affected versionversion=eec522fd0d28106b14a59ab2d658605febe4a3bb
  18. Affected versionversion=efc095b35b23297e419c2ab4fc1ed1a8f0781a29 <d2afc7ecee476f9251dd87444f7fb6a424410922
  19. Affected versionversion=fc7f732984ec91f30be3e574e0644066d07f2b78
  20. Affected versionversion=fe2891a9c43ab87d1a210d61e6438ca6936e2f62 <8f72fd25a57a457866350359ddd27a43caa62c95

What conditions does exploitation require?

Attack vectorlocal
Required privilegesauthenticated

What is affected?

The Linux Kernel Organization · Linux Kernelversion=384a66b89f9540a9a8cb0f48807697dfabaece4c <16ca053c2be5f4f3044dccf7fc19237dc820d394; version=5.10.241 <5.10.261; version=5.15.190 <5.15.212; version=5.4.297 <5.5; version=6.1.149 <6.1.178; version=6.12.43 <6.12.96; version=6.15.11 <6.16; version=6.16.2 <6.17; version=6.17; version=6.6.103 <6.6.145; version=67ecc81f6492275c9c54280532f558483c99c90e <34684a04777358b2b40ac729e54c8e45359e46b3; version=a1a60e79502279f996e55052f50cc14919020475 <0b189b2204f1a2612dc68f8d139fb5b80539e710; version=a431930c9bac518bf99d6b1da526a7f37ddee8d8 <d5b45bad75cd2730b8452aed4d3b20a2b2a12576; version=a431930c9bac518bf99d6b1da526a7f37ddee8d8 <d67aadee19ffdf3cc8520c5a4f4d5b2916d30baf; version=a431930c9bac518bf99d6b1da526a7f37ddee8d8 <f3461b84a4865d9b5e70fbb71da72ae044a3bcd2; version=e7d2dc2421e821e4045775e6dc226378328de6f6; version=eec522fd0d28106b14a59ab2d658605febe4a3bb; version=efc095b35b23297e419c2ab4fc1ed1a8f0781a29 <d2afc7ecee476f9251dd87444f7fb6a424410922; version=fc7f732984ec91f30be3e574e0644066d07f2b78; version=fe2891a9c43ab87d1a210d61e6438ca6936e2f62 <8f72fd25a57a457866350359ddd27a43caa62c95

Published CVSS scores

3.3Amazon LinuxCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CVSS describes severity. EPSS estimates exploitation probability.

Attacks

What attackers are doing with it

Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.

Daily unique IPsNo honeypot observations are available for this CVE in the selected window.

No observations available

Sep 10, 2026Sep 16, 2026
Latest reporting daySep 16, 2026
Latest daily unique IPsUnavailable
Prior 30-day averageUnavailable
SourceShadowserver honeypots (KEV)
Vectorlocal
Privilegesauthenticated
Known exploitationUnconfirmed
Public exploitUnconfirmed

Weakness, pattern, technique

No sourced classifications are available.

Public exploit references

No public exploit references are available in this record.

Labels summarize the accepted research assessment. They do not indicate a test against your environment.

Technologies

Your stack

See the directory against your own environment.

Your stack

Check the software in your environment

Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.

Book a demo