{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-72373","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-08-09T03:40:39.922Z","datePublished":"2026-08-15T05:56:08.564Z","dateUpdated":"2026-08-17T05:43:26.499Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-17T05:43:26.499Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nafs: Fix missing NULL pointer check in afs_break_some_callbacks()\n\nFix afs_break_some_callbacks() to check to see if afs_lookup_volume_rcu()\nreturned NULL (e.g. the specified volume is unknown)."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:N - The bug is reached when an AFS fileserver sends a CB.CallBack/YFSCB.CallBack RPC over RxRPC to the kernel cache-manager listener; processing flows through SRXAFSCB_CallBack() to afs_break_some_callbacks() with no local syscall required.\nAC:L - A malicious or compromised fileserver that already has an encrypted RxRPC callback channel can reliably send a volume-level callback break (vnode=0, unique=0) for an arbitrary unknown volume ID, deterministically driving afs_lookup_volume_rcu() to return NULL and crash.\nPR:N - Exploitation requires no privileges on the victim host; a remote peer authenticated as a known AFS fileserver can deliver the crafted callback break without the attacker holding local user, capability, or namespace rights on the client.\nUI:N - Once AFS is mounted and a server callback connection exists, triggering the NULL dereference needs no further end-user action—the fileserver can unilaterally send the malformed callback notification at any time.\nS:U - Impact is confined to kernel memory in the AFS client callback path (NULL dereference and possible oops/panic); it does not cross a VM, container, or IOMMU security boundary to affect a different authority.\nC:N - The failure mode is a NULL pointer dereference on volume->servers in afs_break_volume_callback(); there is no out-of-bounds access, use-after-free, or other memory corruption that could disclose kernel data.\nI:N - The bug causes an immediate invalid read through a NULL volume pointer and does not provide controlled writes, metadata corruption, or a path to arbitrary code execution beyond crashing the kernel.\nA:H - Hitting afs_break_volume_callback() with a NULL volume dereferences volume->servers under RCU, provoking a kernel oops or panic and denying availability to the entire system until reboot."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/afs/callback.c"],"versions":[{"version":"8230fd8217b7ea76f838ae88e4a5a8e54f37099f","lessThan":"a99a617701186dc68c7b330d35fc2253f48e2ab2","status":"affected","versionType":"git"},{"version":"8230fd8217b7ea76f838ae88e4a5a8e54f37099f","lessThan":"5492799ec5d27be3bd454dcaf046bc7054f637ae","status":"affected","versionType":"git"},{"version":"8230fd8217b7ea76f838ae88e4a5a8e54f37099f","lessThan":"e3e59ff22a0de01ed0cf3a3e25558811abc3b70a","status":"affected","versionType":"git"},{"version":"8230fd8217b7ea76f838ae88e4a5a8e54f37099f","lessThan":"794a01110390c1b76f59ece773fb0fbfd89c6f5c","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/afs/callback.c"],"versions":[{"version":"5.8","status":"affected"},{"version":"0","lessThan":"5.8","status":"unaffected","versionType":"semver"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","status":"unaffected","versionType":"semver"},{"version":"7.2","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.8","versionEndExcluding":"6.12.97"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.8","versionEndExcluding":"6.18.40"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.8","versionEndExcluding":"7.1.5"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.8","versionEndExcluding":"7.2"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/a99a617701186dc68c7b330d35fc2253f48e2ab2"},{"url":"https://git.kernel.org/stable/c/5492799ec5d27be3bd454dcaf046bc7054f637ae"},{"url":"https://git.kernel.org/stable/c/e3e59ff22a0de01ed0cf3a3e25558811abc3b70a"},{"url":"https://git.kernel.org/stable/c/794a01110390c1b76f59ece773fb0fbfd89c6f5c"}],"title":"afs: Fix missing NULL pointer check in afs_break_some_callbacks()","x_generator":{"engine":"bippy-1.2.0"}}}}