CVE-2026-43474 PUBLISHED

fs: init flags_valid before calling vfs_fileattr_get

Assigner: Linux
Reserved: 01.05.2026 Published: 08.05.2026 Updated: 09.05.2026

In the Linux kernel, the following vulnerability has been resolved:

fs: init flags_valid before calling vfs_fileattr_get

syzbot reported a uninit-value bug in [1].

Similar to the "*get" context where the kernel's internal file_kattr structure is initialized before calling vfs_fileattr_get(), we should use the same mechanism when using fa.

[1] BUG: KMSAN: uninit-value in fuse_fileattr_get+0xeb4/0x1450 fs/fuse/ioctl.c:517 fuse_fileattr_get+0xeb4/0x1450 fs/fuse/ioctl.c:517 vfs_fileattr_get fs/file_attr.c:94 [inline] __do_sys_file_getattr fs/file_attr.c:416 [inline]

Local variable fa.i created at: __do_sys_file_getattr fs/file_attr.c:380 [inline] __se_sys_file_getattr+0x8c/0xbd0 fs/file_attr.c:372

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from be7efb2d20d67f334a7de2aef77ae6c69367e646 to 379e19e820dd1c6145426b97467728b3b89c0b42 (excl.)
  • affected from be7efb2d20d67f334a7de2aef77ae6c69367e646 to b8c182b2c8c44c6016b11d8af61715ad7ef958a1 (excl.)
  • affected from be7efb2d20d67f334a7de2aef77ae6c69367e646 to cb184dd19154fc486fa3d9e02afe70a97e54e055 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 6.17 is affected
  • unaffected from 0 to 6.17 (excl.)
  • unaffected from 6.18.19 to 6.18.* (incl.)
  • unaffected from 6.19.9 to 6.19.* (incl.)
  • unaffected from 7.0 to * (incl.)

References