« Volver al listado

CVE-2026-74426

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

afs: fix NULL pointer dereference in afs_get_tree()

afs_alloc_sbi() uses kzalloc for memory allocation. And, if ctx->dyn_root is not null, as->cell and as->volume are null. In trace_afs_get_tree() they are dereferenced.

Found by Linux Verification Center (linuxtesting.org) with Syzkaller.

Detalles técnicos trazas, registros y código del informe original
KASAN error message:

KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007]
CPU: 2 PID: 18478 Comm: syz-executor.7 Not tainted 5.10.246-syzkaller #0
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.12.0-1
04/01/2014
RIP: 0010:perf_trace_afs_get_tree+0x1d9/0x550
include/trace/events/afs.h:1365

Call Trace:
trace_afs_get_tree include/trace/events/afs.h:1365 [inline]
afs_get_tree+0x922/0x1350 fs/afs/super.c:599
vfs_get_tree+0x8e/0x300 fs/super.c:1572
do_new_mount fs/namespace.c:3011 [inline]
path_mount+0x14a5/0x2220 fs/namespace.c:3341
do_mount fs/namespace.c:3354 [inline]
__do_sys_mount fs/namespace.c:3562 [inline]
__se_sys_mount fs/namespace.c:3539 [inline]
__x64_sys_mount+0x283/0x300 fs/namespace.c:3539
 do_syscall_64+0x33/0x50 arch/x86/entry/common.c:46
entry_SYSCALL_64_after_hwframe+0x67/0xd1

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-74426",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "80548b03991f58758a336424a90bf9f988e3b077",
              "lessThan": "67fb48c4a0874953212321cd5d57fdb4900dbc31",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "80548b03991f58758a336424a90bf9f988e3b077",
              "lessThan": "d648cc2069eb081707c061849046d909f57c78b1",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "80548b03991f58758a336424a90bf9f988e3b077",
              "lessThan": "d5b17474feed3c30991f07affa2473adbad95055",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "80548b03991f58758a336424a90bf9f988e3b077",
              "lessThan": "867b3ea146a041023bfcd258e6db516b1bb28f19",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "80548b03991f58758a336424a90bf9f988e3b077",
              "lessThan": "ea19edf71721cd42f923e3c70f4ff995b422fe3b",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "80548b03991f58758a336424a90bf9f988e3b077",
              "lessThan": "23b3d457d8387bcb2a61063a9e520063ada9335f",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "80548b03991f58758a336424a90bf9f988e3b077",
              "lessThan": "70b2842734d831c908474779bb8a76daf55f782c",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "80548b03991f58758a336424a90bf9f988e3b077",
              "lessThan": "0b70716081c6462be9b2928ad736d0d527b09678",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "fs/afs/super.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.2"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "5.2",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.261",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.212",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.178",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.145",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.97",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.40",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.1.5",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "fs/afs/super.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-08-15T06:22:44.690",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/0b70716081c6462be9b2928ad736d0d527b09678",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/23b3d457d8387bcb2a61063a9e520063ada9335f",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/67fb48c4a0874953212321cd5d57fdb4900dbc31",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/70b2842734d831c908474779bb8a76daf55f782c",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/867b3ea146a041023bfcd258e6db516b1bb28f19",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/d5b17474feed3c30991f07affa2473adbad95055",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/d648cc2069eb081707c061849046d909f57c78b1",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/ea19edf71721cd42f923e3c70f4ff995b422fe3b",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nafs: fix NULL pointer dereference in afs_get_tree()\n\nafs_alloc_sbi() uses kzalloc for memory allocation. And, if\nctx->dyn_root is not null, as->cell and as->volume are null.\nIn trace_afs_get_tree() they are dereferenced.\n\nKASAN error message:\n\nKASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007]\nCPU: 2 PID: 18478 Comm: syz-executor.7 Not tainted 5.10.246-syzkaller #0\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.12.0-1\n04/01/2014\nRIP: 0010:perf_trace_afs_get_tree+0x1d9/0x550\ninclude/trace/events/afs.h:1365\n\nCall Trace:\ntrace_afs_get_tree include/trace/events/afs.h:1365 [inline]\nafs_get_tree+0x922/0x1350 fs/afs/super.c:599\nvfs_get_tree+0x8e/0x300 fs/super.c:1572\ndo_new_mount fs/namespace.c:3011 [inline]\npath_mount+0x14a5/0x2220 fs/namespace.c:3341\ndo_mount fs/namespace.c:3354 [inline]\n__do_sys_mount fs/namespace.c:3562 [inline]\n__se_sys_mount fs/namespace.c:3539 [inline]\n__x64_sys_mount+0x283/0x300 fs/namespace.c:3539\n do_syscall_64+0x33/0x50 arch/x86/entry/common.c:46\nentry_SYSCALL_64_after_hwframe+0x67/0xd1\n\nFound by Linux Verification Center (linuxtesting.org) with Syzkaller."
    }
  ],
  "lastModified": "2026-08-17T06:19:38.110",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}