Linux Kernel Uninit-Value Bug in vfs_fileattr_get (CVE-2026-43474)
CVE-2026-43474 Published on May 8, 2026
fs: init flags_valid before calling vfs_fileattr_get
In the Linux kernel, the following vulnerability has been resolved:
fs: init flags_valid before calling vfs_fileattr_get
syzbot reported a uninit-value bug in [1].
Similar to the "*get" context where the kernel's internal file_kattr
structure is initialized before calling vfs_fileattr_get(), we should
use the same mechanism when using fa.
[1]
BUG: KMSAN: uninit-value in fuse_fileattr_get+0xeb4/0x1450 fs/fuse/ioctl.c:517
fuse_fileattr_get+0xeb4/0x1450 fs/fuse/ioctl.c:517
vfs_fileattr_get fs/file_attr.c:94 [inline]
__do_sys_file_getattr fs/file_attr.c:416 [inline]
Local variable fa.i created at:
__do_sys_file_getattr fs/file_attr.c:380 [inline]
__se_sys_file_getattr+0x8c/0xbd0 fs/file_attr.c:372
Products Associated with CVE-2026-43474
Want to know whenever a new CVE is published for Linux Kernel? stack.watch will email you.
Affected Versions
Linux:- Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 and below 379e19e820dd1c6145426b97467728b3b89c0b42 is affected.
- Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 and below b8c182b2c8c44c6016b11d8af61715ad7ef958a1 is affected.
- Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 and below cb184dd19154fc486fa3d9e02afe70a97e54e055 is affected.
- Version 6.18.19, <= 6.18.* is unaffected.
- Version 6.19.9, <= 6.19.* is unaffected.
- Version 7.0, <= * is unaffected.