afs: fix NULL pointer dereference in afs_get_tree()

Summary

CVECVE-2026-74426
StatePUBLISHED
AssignerLinux
Source PriorityCVE Program / NVD first with legacy fallback
Published2026-08-15 06:22:44 UTC
Updated2026-08-15 06:22:44 UTC
DescriptionIn the Linux kernel, the following vulnerability has been resolved: afs: fix NULL pointer dereference in afs_get_tree() afs_alloc_sbi() uses kzalloc for memory allocation. And, if ctx->dyn_root is not null, as->cell and as->volume are null. In trace_afs_get_tree() they are dereferenced. KASAN error message: KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007] CPU: 2 PID: 18478 Comm: syz-executor.7 Not tainted 5.10.246-syzkaller #0 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.12.0-1 04/01/2014 RIP: 0010:perf_trace_afs_get_tree+0x1d9/0x550 include/trace/events/afs.h:1365 Call Trace: trace_afs_get_tree include/trace/events/afs.h:1365 [inline] afs_get_tree+0x922/0x1350 fs/afs/super.c:599 vfs_get_tree+0x8e/0x300 fs/super.c:1572 do_new_mount fs/namespace.c:3011 [inline] path_mount+0x14a5/0x2220 fs/namespace.c:3341 do_mount fs/namespace.c:3354 [inline] __do_sys_mount fs/namespace.c:3562 [inline] __se_sys_mount fs/namespace.c:3539 [inline] __x64_sys_mount+0x283/0x300 fs/namespace.c:3539 do_syscall_64+0x33/0x50 arch/x86/entry/common.c:46 entry_SYSCALL_64_after_hwframe+0x67/0xd1 Found by Linux Verification Center (linuxtesting.org) with Syzkaller.

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Linux Linux affected 80548b03991f58758a336424a90bf9f988e3b077 67fb48c4a0874953212321cd5d57fdb4900dbc31 git Not specified
CNA Linux Linux affected 80548b03991f58758a336424a90bf9f988e3b077 d648cc2069eb081707c061849046d909f57c78b1 git Not specified
CNA Linux Linux affected 80548b03991f58758a336424a90bf9f988e3b077 d5b17474feed3c30991f07affa2473adbad95055 git Not specified
CNA Linux Linux affected 80548b03991f58758a336424a90bf9f988e3b077 867b3ea146a041023bfcd258e6db516b1bb28f19 git Not specified
CNA Linux Linux affected 80548b03991f58758a336424a90bf9f988e3b077 ea19edf71721cd42f923e3c70f4ff995b422fe3b git Not specified
CNA Linux Linux affected 80548b03991f58758a336424a90bf9f988e3b077 23b3d457d8387bcb2a61063a9e520063ada9335f git Not specified
CNA Linux Linux affected 80548b03991f58758a336424a90bf9f988e3b077 70b2842734d831c908474779bb8a76daf55f782c git Not specified
CNA Linux Linux affected 80548b03991f58758a336424a90bf9f988e3b077 0b70716081c6462be9b2928ad736d0d527b09678 git Not specified
CNA Linux Linux affected 5.2 Not specified
CNA Linux Linux unaffected 5.2 semver Not specified
CNA Linux Linux unaffected 5.10.261 5.10.* semver Not specified
CNA Linux Linux unaffected 5.15.212 5.15.* semver Not specified
CNA Linux Linux unaffected 6.1.178 6.1.* semver Not specified
CNA Linux Linux unaffected 6.6.145 6.6.* semver Not specified
CNA Linux Linux unaffected 6.12.97 6.12.* semver Not specified
CNA Linux Linux unaffected 6.18.40 6.18.* semver Not specified
CNA Linux Linux unaffected 7.1.5 7.1.* semver Not specified
CNA Linux Linux unaffected 7.2-rc2 * original_commit_for_fix Not specified

References

ReferenceSourceLinkTags
git.kernel.org/stable/c/d648cc2069eb081707c061849046d909f57c78b1 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/67fb48c4a0874953212321cd5d57fdb4900dbc31 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/70b2842734d831c908474779bb8a76daf55f782c 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/0b70716081c6462be9b2928ad736d0d527b09678 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/d5b17474feed3c30991f07affa2473adbad95055 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/867b3ea146a041023bfcd258e6db516b1bb28f19 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/23b3d457d8387bcb2a61063a9e520063ada9335f 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/ea19edf71721cd42f923e3c70f4ff995b422fe3b 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report