LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-46299

linux · linux kernel

Published
CVSS7
Severityhigh
WeaknessCWE-667
ExploitedNot in CISA KEV

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Description

In the Linux kernel, the following vulnerability has been resolved: hfsplus: fix held lock freed on hfsplus_fill_super() hfsplus_fill_super() calls hfs_find_init() to initialize a search structure, which acquires tree->tree_lock. If the subsequent call to hfsplus_cat_build_key() fails, the function jumps to the out_put_root error label without releasing the lock. The later cleanup path then frees the tree data structure with the lock still held, triggering a held lock freed warning. Fix this by adding the missing hfs_find_exit(&fd) call before jumping to the out_put_root error label. This ensures that tree->tree_lock is properly released on the error path. The bug was originally detected

References

← Back to the CVE Tracker

Our coverage of CVE-2026-46299

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-46299.