afs: Fix callback service message parsers to pass through -EAGAIN

Summary

CVECVE-2026-72374
StatePUBLISHED
AssignerLinux
Source PriorityCVE Program / NVD first with legacy fallback
Published2026-08-15 06:22:10 UTC
Updated2026-08-17 06:18:41 UTC
DescriptionIn the Linux kernel, the following vulnerability has been resolved: afs: Fix callback service message parsers to pass through -EAGAIN The AFS filesystem client uses an rxrpc server to listen for callback notifications. Each callback call type handler has a delivery function that parses the incoming request stream, and this should return -EAGAIN the last packet hasn't yet been seen, but all currently queued received data is consumed. afs_extract_data() does this, but the -EAGAIN return is switched to 0 inadvertantly Fix callback service message parsers to pass through -EAGAIN

Risk And Classification

Primary CVSS: v3.1 7.5 HIGH from 416baaa9-dc9f-4396-8d5f-8c081fb06d67

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS: 0.007160000 probability, percentile 0.507270000 (date 2026-08-17)


VersionSourceTypeScoreSeverityVector
3.1416baaa9-dc9f-4396-8d5f-8c081fb06d67Secondary7.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
3.1CNADECLARED7.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CVSS v3.1 Breakdown

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Linux Linux affected d001648ec7cf8b21ae9eec8b9ba4a18295adfb14 26b737b3769e92493fe94c34620399d93ca231ae git Not specified
CNA Linux Linux affected d001648ec7cf8b21ae9eec8b9ba4a18295adfb14 09c67a7ded481482155b836c8c7f078a3075f8de git Not specified
CNA Linux Linux affected d001648ec7cf8b21ae9eec8b9ba4a18295adfb14 239cd337c9d047e7097f5b2ebbb41ddfb8180bc6 git Not specified
CNA Linux Linux affected d001648ec7cf8b21ae9eec8b9ba4a18295adfb14 5a39b145a8fb49f316e7ec1f29ba51d68095c7e4 git Not specified
CNA Linux Linux affected d001648ec7cf8b21ae9eec8b9ba4a18295adfb14 772850871a2e772e26f9d93f1e9ddd413b3eeaa4 git Not specified
CNA Linux Linux affected d001648ec7cf8b21ae9eec8b9ba4a18295adfb14 0acbc09d2aca0432af45cec114f20d55ceafaec4 git Not specified
CNA Linux Linux affected d001648ec7cf8b21ae9eec8b9ba4a18295adfb14 f14dd036fad3d359f26f1282199cec06b3a9362b git Not specified
CNA Linux Linux affected d001648ec7cf8b21ae9eec8b9ba4a18295adfb14 0f36469d7ce98b362934113c550d08bb0c784231 git Not specified
CNA Linux Linux affected 4.9 Not specified
CNA Linux Linux unaffected 4.9 semver Not specified
CNA Linux Linux unaffected 5.10.261 5.10.* semver Not specified
CNA Linux Linux unaffected 5.15.212 5.15.* semver Not specified
CNA Linux Linux unaffected 6.1.178 6.1.* semver Not specified
CNA Linux Linux unaffected 6.6.145 6.6.* semver Not specified
CNA Linux Linux unaffected 6.12.97 6.12.* semver Not specified
CNA Linux Linux unaffected 6.18.40 6.18.* semver Not specified
CNA Linux Linux unaffected 7.1.5 7.1.* semver Not specified
CNA Linux Linux unaffected 7.2 * original_commit_for_fix Not specified

References

ReferenceSourceLinkTags
git.kernel.org/stable/c/0acbc09d2aca0432af45cec114f20d55ceafaec4 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/239cd337c9d047e7097f5b2ebbb41ddfb8180bc6 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/f14dd036fad3d359f26f1282199cec06b3a9362b 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/09c67a7ded481482155b836c8c7f078a3075f8de 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/0f36469d7ce98b362934113c550d08bb0c784231 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/5a39b145a8fb49f316e7ec1f29ba51d68095c7e4 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/26b737b3769e92493fe94c34620399d93ca231ae 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/772850871a2e772e26f9d93f1e9ddd413b3eeaa4 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report