Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-86112.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-86112
Upstream
Published
2026-05-08T15:17:00Z
Modified
2026-08-28T17:47:58.492923725Z
Summary
CVE-2026-43474 affecting package kernel for versions less than 6.6.138.1-1
Details

In the Linux kernel, the following vulnerability has been resolved:

fs: init flagsvalid before calling vfsfileattr_get

syzbot reported a uninit-value bug in [1].

Similar to the "*get" context where the kernel's internal filekattr structure is initialized before calling vfsfileattr_get(), we should use the same mechanism when using fa.

[1] BUG: KMSAN: uninit-value in fusefileattrget+0xeb4/0x1450 fs/fuse/ioctl.c:517 fusefileattrget+0xeb4/0x1450 fs/fuse/ioctl.c:517 vfsfileattrget fs/file_attr.c:94 [inline] __dosysfilegetattr fs/fileattr.c:416 [inline]

Local variable fa.i created at: __dosysfilegetattr fs/fileattr.c:380 [inline] __sesysfilegetattr+0x8c/0xbd0 fs/fileattr.c:372

References

Affected packages

Azure Linux:3 / kernel

Package

Name
kernel
Purl
pkg:rpm/azure-linux/kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.6.138.1-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-86112.json"