CVE-2026-43228

Source
https://cve.org/CVERecord?id=CVE-2026-43228
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-43228.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-43228
Downstream
Related
Published
2026-05-06T11:28:26.292Z
Modified
2026-07-15T01:49:21.205990045Z
Summary
hfs: Replace BUG_ON with error handling for CNID count checks
Details

In the Linux kernel, the following vulnerability has been resolved:

hfs: Replace BUG_ON with error handling for CNID count checks

In a06ec283e125 nextid, foldercount, and filecount in the super block info were expanded to 64 bits, and BUGONs were added to detect overflow. This triggered an error reported by syzbot: if the MDB is corrupted, the BUG_ON is triggered. This patch replaces this mechanism with proper error handling and resolves the syzbot reported bug.

Singed-off-by: Jori Koolstra jkoolstra@xs4all.nl

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/43xxx/CVE-2026-43228.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
a06ec283e125e334155fe13005c76c9f484ce759
Fixed
b6536c1ced315fa645576d3a39c6e07f2a472962
Fixed
b226804532a875c10276168dc55ce752944096bd

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-43228.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.18.0
Fixed
6.19.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-43228.json"