From: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
To: linux-cve-announce@vger.kernel.org
Cc: Greg Kroah-Hartman <gregkh@kernel.org>
Subject: CVE-2026-74426: afs: fix NULL pointer dereference in afs_get_tree()
Date: Sat, 15 Aug 2026 15:12:33 +0900 [thread overview]
Message-ID: <2026081513-CVE-2026-74426-3f85@gregkh> (raw)
From: Greg Kroah-Hartman <gregkh@kernel.org>
Description
===========
In the Linux kernel, the following vulnerability has been resolved:
afs: fix NULL pointer dereference in afs_get_tree()
afs_alloc_sbi() uses kzalloc for memory allocation. And, if
ctx->dyn_root is not null, as->cell and as->volume are null.
In trace_afs_get_tree() they are dereferenced.
KASAN error message:
KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007]
CPU: 2 PID: 18478 Comm: syz-executor.7 Not tainted 5.10.246-syzkaller #0
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.12.0-1
04/01/2014
RIP: 0010:perf_trace_afs_get_tree+0x1d9/0x550
include/trace/events/afs.h:1365
Call Trace:
trace_afs_get_tree include/trace/events/afs.h:1365 [inline]
afs_get_tree+0x922/0x1350 fs/afs/super.c:599
vfs_get_tree+0x8e/0x300 fs/super.c:1572
do_new_mount fs/namespace.c:3011 [inline]
path_mount+0x14a5/0x2220 fs/namespace.c:3341
do_mount fs/namespace.c:3354 [inline]
__do_sys_mount fs/namespace.c:3562 [inline]
__se_sys_mount fs/namespace.c:3539 [inline]
__x64_sys_mount+0x283/0x300 fs/namespace.c:3539
do_syscall_64+0x33/0x50 arch/x86/entry/common.c:46
entry_SYSCALL_64_after_hwframe+0x67/0xd1
Found by Linux Verification Center (linuxtesting.org) with Syzkaller.
The Linux kernel CVE team has assigned CVE-2026-74426 to this issue.
Affected and fixed versions
===========================
Issue introduced in 5.2 with commit 80548b03991f58758a336424a90bf9f988e3b077 and fixed in 5.10.261 with commit 67fb48c4a0874953212321cd5d57fdb4900dbc31
Issue introduced in 5.2 with commit 80548b03991f58758a336424a90bf9f988e3b077 and fixed in 5.15.212 with commit d648cc2069eb081707c061849046d909f57c78b1
Issue introduced in 5.2 with commit 80548b03991f58758a336424a90bf9f988e3b077 and fixed in 6.1.178 with commit d5b17474feed3c30991f07affa2473adbad95055
Issue introduced in 5.2 with commit 80548b03991f58758a336424a90bf9f988e3b077 and fixed in 6.6.145 with commit 867b3ea146a041023bfcd258e6db516b1bb28f19
Issue introduced in 5.2 with commit 80548b03991f58758a336424a90bf9f988e3b077 and fixed in 6.12.97 with commit ea19edf71721cd42f923e3c70f4ff995b422fe3b
Issue introduced in 5.2 with commit 80548b03991f58758a336424a90bf9f988e3b077 and fixed in 6.18.40 with commit 23b3d457d8387bcb2a61063a9e520063ada9335f
Issue introduced in 5.2 with commit 80548b03991f58758a336424a90bf9f988e3b077 and fixed in 7.1.5 with commit 70b2842734d831c908474779bb8a76daf55f782c
Issue introduced in 5.2 with commit 80548b03991f58758a336424a90bf9f988e3b077 and fixed in 7.2-rc2 with commit 0b70716081c6462be9b2928ad736d0d527b09678
Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.
Unaffected versions might change over time as fixes are backported to
older supported kernel versions. The official CVE entry at
https://cve.org/CVERecord/?id=CVE-2026-74426
will be updated if fixes are backported, please check that for the most
up to date information about this issue.
Affected files
==============
The file(s) affected by this issue are:
fs/afs/super.c
Mitigation
==========
The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes. Individual
changes are never tested alone, but rather are part of a larger kernel
release. Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all. If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
https://git.kernel.org/stable/c/67fb48c4a0874953212321cd5d57fdb4900dbc31
https://git.kernel.org/stable/c/d648cc2069eb081707c061849046d909f57c78b1
https://git.kernel.org/stable/c/d5b17474feed3c30991f07affa2473adbad95055
https://git.kernel.org/stable/c/867b3ea146a041023bfcd258e6db516b1bb28f19
https://git.kernel.org/stable/c/ea19edf71721cd42f923e3c70f4ff995b422fe3b
https://git.kernel.org/stable/c/23b3d457d8387bcb2a61063a9e520063ada9335f
https://git.kernel.org/stable/c/70b2842734d831c908474779bb8a76daf55f782c
https://git.kernel.org/stable/c/0b70716081c6462be9b2928ad736d0d527b09678
reply other threads:[~2026-08-15 6:41 UTC|newest]
Thread overview: [no followups] expand[flat|nested] mbox.gz Atom feed
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=2026081513-CVE-2026-74426-3f85@gregkh \
--to=gregkh@linuxfoundation.org \
--cc=cve@kernel.org \
--cc=gregkh@kernel.org \
--cc=linux-cve-announce@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.