In the Linux kernel, the following vulnerability has been resolved:
fs: init flags_valid before calling vfs_fileattr_get
syzbot reported a uninit-value bug in [1].
Similar to the "*get" context where the kernel's internal file_kattr
structure is initialized before calling vfs_fileattr_get(), we should
use the same mechanism when using fa.
[1]
BUG: KMSAN: uninit-value in fuse_fileattr_get+0xeb4/0x1450 fs/fuse/ioctl.c:517
fuse_fileattr_get+0xeb4/0x1450 fs/fuse/ioctl.c:517
vfs_fileattr_get fs/file_attr.c:94 [inline]
__do_sys_file_getattr fs/file_attr.c:416 [inline]
Local variable fa.i created at:
__do_sys_file_getattr fs/file_attr.c:380 [inline]
__se_sys_file_getattr+0x8c/0xbd0 fs/file_attr.c:372
References
Configurations
Configuration 1 (hide)
|
History
21 May 2026, 14:59
| Type | Values Removed | Values Added |
|---|---|---|
| CPE |
21 May 2026, 13:12
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:7.0:rc1:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:7.0:rc2:*:*:*:*:*:* |
|
| First Time |
Linux linux Kernel
Linux |
|
| CWE | CWE-908 | |
| References | () https://git.kernel.org/stable/c/379e19e820dd1c6145426b97467728b3b89c0b42 - Patch | |
| References | () https://git.kernel.org/stable/c/b8c182b2c8c44c6016b11d8af61715ad7ef958a1 - Patch | |
| References | () https://git.kernel.org/stable/c/cb184dd19154fc486fa3d9e02afe70a97e54e055 - Patch | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.5 |
08 May 2026, 15:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-08 15:17
Updated : 2026-05-21 14:59
NVD link : CVE-2026-43474
Mitre link : CVE-2026-43474
CVE.ORG link : CVE-2026-43474
JSON object : View
Products Affected
linux
- linux_kernel
CWE
CWE-908
Use of Uninitialized Resource
