« Volver al listado

CVE-2026-72377

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

afs: Remove setting of AS_RELEASE_ALWAYS for symlinks and mountpoints

Regular AFS files correctly use afs_file_aops which have release_folio set as netfs_release_folio, so AS_RELEASE_ALWAYS is valid for them when fscache is enabled (set via afs_vnode_set_cache()). Symlinks and mountpoints in AFS use afs_dir_aops, which does not provide a release_folio callback. However, afs_apply_status() unconditionally calls mapping_set_release_always() for these.

In such case when memory management code attempts to release folios, filemap_release_folio() checks folio_needs_release() which returns true due to AS_RELEASE_ALWAYS being set.

Leer descripción completaMostrar menos

Since there is no release_folio callback, it falls through to try_to_free_buffers(), which at present expects buffer_heads to be not null. For symlinks and mountpoints without buffer_heads, this causes pointer dereference.

[dh: Added more bits that were missed]

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-72377",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "eae9e78951bb02a7b94a9adef6e981413d13c564",
              "lessThan": "9d6b0f6d437e2f8350e08678e5e1d20c11c364f3",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "eae9e78951bb02a7b94a9adef6e981413d13c564",
              "lessThan": "81e985b4c3a6cbcc443fcdcd3ebda7fcc845d459",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "fs/afs/inode.c",
            "fs/afs/internal.h"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.14"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.14",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "7.1.5",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "fs/afs/inode.c",
            "fs/afs/internal.h"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-08-15T06:22:11.180",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/81e985b4c3a6cbcc443fcdcd3ebda7fcc845d459",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/9d6b0f6d437e2f8350e08678e5e1d20c11c364f3",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nafs: Remove setting of AS_RELEASE_ALWAYS for symlinks and mountpoints\n\nRegular AFS files correctly use afs_file_aops which have release_folio\nset as netfs_release_folio, so AS_RELEASE_ALWAYS is valid for them\nwhen fscache is enabled (set via afs_vnode_set_cache()).\nSymlinks and mountpoints in AFS use afs_dir_aops, which does not provide\na release_folio callback. However, afs_apply_status() unconditionally\ncalls mapping_set_release_always() for these.\n\nIn such case when memory management code attempts to release folios,\nfilemap_release_folio() checks folio_needs_release() which\nreturns true due to AS_RELEASE_ALWAYS being set. Since there is no\nrelease_folio callback, it falls through to try_to_free_buffers(),\nwhich at present expects buffer_heads to be not null. For symlinks\nand mountpoints without buffer_heads, this causes pointer dereference.\n\n[dh: Added more bits that were missed]"
    }
  ],
  "lastModified": "2026-08-17T06:18:42.060",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}