CVE-2026-74426: afs: fix NULL pointer dereference in afs_get_tree()
Greg Kroah-Hartman <[email protected]>
| Newsgroups | org.kernel.vger.linux-cve-announce |
|---|---|
| Message-ID | <2026081513-CVE-2026-74426-3f85@gregkh> |
From: Greg Kroah-Hartman <[email protected]> Description =========== In the Linux kernel, the following vulnerability has been resolved: afs: fix NULL pointer dereference in afs_get_tree() afs_alloc_sbi() uses kzalloc for memory allocation. And, if ctx->dyn_root is not null, as->cell and as->volume are null. In trace_afs_get_tree() they are dereferenced. KASAN error message: KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007] CPU: 2 PID: 18478 Comm: syz-executor.7 Not tainted 5.10.246-syzkaller #0 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.12.0-1 04/01/2014 RIP: 0010:perf_trace_afs_get_tree+0x1d9/0x550 include/trace/events/afs.h:1365 Call Trace: trace_afs_get_tree include/trace/events/afs.h:1365 [inline] afs_get_tree+0x922/0x1350 fs/afs/super.c:599 vfs_get_tree+0x8e/0x300 fs/super.c:1572 do_new_mount fs/namespace.c:3011 [inline] path_mount+0x14a5/0x2220 fs/namespace.c:3341 do_mount fs/namespace.c:3354 [inline] __do_sys_mount fs/namespace.c:3562 [inline] __se_sys_mount fs/namespace.c:3539 [inline] __x64_sys_mount+0x283/0x300 fs/namespace.c:3539 do_syscall_64+0x33/0x50 arch/x86/entry/common.c:46 entry_SYSCALL_64_after_hwframe+0x67/0xd1 Found by Linux Verification Center (linuxtesting.org) with Syzkaller. The Linux kernel CVE team has assigned CVE-2026-74426 to this issue. Affected and fixed versions =========================== Issue introduced in 5.2 with commit 80548b03991f58758a336424a90bf9f988e3b077 and fixed in 5.10.261 with commit 67fb48c4a0874953212321cd5d57fdb4900dbc31 Issue introduced in 5.2 with commit 80548b03991f58758a336424a90bf9f988e3b077 and fixed in 5.15.212 with commit d648cc2069eb081707c061849046d909f57c78b1 Issue introduced in 5.2 with commit 80548b03991f58758a336424a90bf9f988e3b077 and fixed in 6.1.178 with commit d5b17474feed3c30991f07affa2473adbad95055 Issue introduced in 5.2 with commit 80548b03991f58758a336424a90bf9f988e3b077 and fixed in 6.6.145 with commit 867b3ea146a041023bfcd258e6db516b1bb28f19 Issue introduced in 5.2 with commit 80548b03991f58758a336424a90bf9f988e3b077 and fixed in 6.12.97 with commit ea19edf71721cd42f923e3c70f4ff995b422fe3b Issue introduced in 5.2 with commit 80548b03991f58758a336424a90bf9f988e3b077 and fixed in 6.18.40 with commit 23b3d457d8387bcb2a61063a9e520063ada9335f Issue introduced in 5.2 with commit 80548b03991f58758a336424a90bf9f988e3b077 and fixed in 7.1.5 with commit 70b2842734d831c908474779bb8a76daf55f782c Issue introduced in 5.2 with commit 80548b03991f58758a336424a90bf9f988e3b077 and fixed in 7.2-rc2 with commit 0b70716081c6462be9b2928ad736d0d527b09678 Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-74426 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: fs/afs/super.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/67fb48c4a0874953212321cd5d57fdb4900dbc31 https://git.kernel.org/stable/c/d648cc2069eb081707c061849046d909f57c78b1 https://git.kernel.org/stable/c/d5b17474feed3c30991f07affa2473adbad95055 https://git.kernel.org/stable/c/867b3ea146a041023bfcd258e6db516b1bb28f19 https://git.kernel.org/stable/c/ea19edf71721cd42f923e3c70f4ff995b422fe3b https://git.kernel.org/stable/c/23b3d457d8387bcb2a61063a9e520063ada9335f https://git.kernel.org/stable/c/70b2842734d831c908474779bb8a76daf55f782c https://git.kernel.org/stable/c/0b70716081c6462be9b2928ad736d0d527b09678