CVE-2026-74426: afs: fix NULL pointer dereference in afs_get_tree()

Greg Kroah-Hartman <[email protected]>
Newsgroups org.kernel.vger.linux-cve-announce
Message-ID <2026081513-CVE-2026-74426-3f85@gregkh>
From: Greg Kroah-Hartman <[email protected]>

Description
===========

In the Linux kernel, the following vulnerability has been resolved:

afs: fix NULL pointer dereference in afs_get_tree()

afs_alloc_sbi() uses kzalloc for memory allocation. And, if
ctx->dyn_root is not null, as->cell and as->volume are null.
In trace_afs_get_tree() they are dereferenced.

KASAN error message:

KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007]
CPU: 2 PID: 18478 Comm: syz-executor.7 Not tainted 5.10.246-syzkaller #0
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.12.0-1
04/01/2014
RIP: 0010:perf_trace_afs_get_tree+0x1d9/0x550
include/trace/events/afs.h:1365

Call Trace:
trace_afs_get_tree include/trace/events/afs.h:1365 [inline]
afs_get_tree+0x922/0x1350 fs/afs/super.c:599
vfs_get_tree+0x8e/0x300 fs/super.c:1572
do_new_mount fs/namespace.c:3011 [inline]
path_mount+0x14a5/0x2220 fs/namespace.c:3341
do_mount fs/namespace.c:3354 [inline]
__do_sys_mount fs/namespace.c:3562 [inline]
__se_sys_mount fs/namespace.c:3539 [inline]
__x64_sys_mount+0x283/0x300 fs/namespace.c:3539
 do_syscall_64+0x33/0x50 arch/x86/entry/common.c:46
entry_SYSCALL_64_after_hwframe+0x67/0xd1

Found by Linux Verification Center (linuxtesting.org) with Syzkaller.

The Linux kernel CVE team has assigned CVE-2026-74426 to this issue.


Affected and fixed versions
===========================

	Issue introduced in 5.2 with commit 80548b03991f58758a336424a90bf9f988e3b077 and fixed in 5.10.261 with commit 67fb48c4a0874953212321cd5d57fdb4900dbc31
	Issue introduced in 5.2 with commit 80548b03991f58758a336424a90bf9f988e3b077 and fixed in 5.15.212 with commit d648cc2069eb081707c061849046d909f57c78b1
	Issue introduced in 5.2 with commit 80548b03991f58758a336424a90bf9f988e3b077 and fixed in 6.1.178 with commit d5b17474feed3c30991f07affa2473adbad95055
	Issue introduced in 5.2 with commit 80548b03991f58758a336424a90bf9f988e3b077 and fixed in 6.6.145 with commit 867b3ea146a041023bfcd258e6db516b1bb28f19
	Issue introduced in 5.2 with commit 80548b03991f58758a336424a90bf9f988e3b077 and fixed in 6.12.97 with commit ea19edf71721cd42f923e3c70f4ff995b422fe3b
	Issue introduced in 5.2 with commit 80548b03991f58758a336424a90bf9f988e3b077 and fixed in 6.18.40 with commit 23b3d457d8387bcb2a61063a9e520063ada9335f
	Issue introduced in 5.2 with commit 80548b03991f58758a336424a90bf9f988e3b077 and fixed in 7.1.5 with commit 70b2842734d831c908474779bb8a76daf55f782c
	Issue introduced in 5.2 with commit 80548b03991f58758a336424a90bf9f988e3b077 and fixed in 7.2-rc2 with commit 0b70716081c6462be9b2928ad736d0d527b09678

Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.

Unaffected versions might change over time as fixes are backported to
older supported kernel versions.  The official CVE entry at
	https://cve.org/CVERecord/?id=CVE-2026-74426
will be updated if fixes are backported, please check that for the most
up to date information about this issue.


Affected files
==============

The file(s) affected by this issue are:
	fs/afs/super.c


Mitigation
==========

The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes.  Individual
changes are never tested alone, but rather are part of a larger kernel
release.  Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all.  If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
	https://git.kernel.org/stable/c/67fb48c4a0874953212321cd5d57fdb4900dbc31
	https://git.kernel.org/stable/c/d648cc2069eb081707c061849046d909f57c78b1
	https://git.kernel.org/stable/c/d5b17474feed3c30991f07affa2473adbad95055
	https://git.kernel.org/stable/c/867b3ea146a041023bfcd258e6db516b1bb28f19
	https://git.kernel.org/stable/c/ea19edf71721cd42f923e3c70f4ff995b422fe3b
	https://git.kernel.org/stable/c/23b3d457d8387bcb2a61063a9e520063ada9335f
	https://git.kernel.org/stable/c/70b2842734d831c908474779bb8a76daf55f782c
	https://git.kernel.org/stable/c/0b70716081c6462be9b2928ad736d0d527b09678
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.