Description
In the Linux kernel, the following vulnerability has been resolved:

afs: Fix lack of locking around modifications of net->cells_dyn_ino

Fix the lack of locking around modifications of net->cells_dyn_ino by
taking net->cells_lock exclusively. This also requires to cell to be
removed from net->cells_dyn_ino in afs_destroy_cell_work() rather than in
afs_cell_destroy() as the latter runs in RCU cleanup context and sleeping
locks cannot be taken there.
Published: 2026-08-15
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Linux kernel contained a flaw in the AFS implementation where modifications to the net\-cells_dyn_ino structure were performed without acquiring the required net\-cells_lock. This omission creates a race condition that can lead to memory corruption, kernel panics, or denial of service if an attacker can orchestrate concurrent modifications. The flaw falls under the CWE category of improper synchronization allowing concurrent data corruption.

Affected Systems

The vulnerability is present in the Linux kernel whenever the AFS networking subsystem is compiled and enabled. The affected code path resides in the cells_dyn_ino data structure. Exact version ranges are not provided, so all kernel versions prior to the patch that implement this code are potentially vulnerable.

Risk and Exploitability

The CVSS score of 7.8 indicates a high severity flaw, while the EPSS score of less than 1% shows a very low but nonzero likelihood of exploitation. The defect is not listed in KEV. Based on the nature of the race condition, exploitation would require a local privileged or root attacker able to influence kernel data structures, likely through crafted network traffic or exploitation of the AFS mount. While the exact attack vector is not detailed, the lack of proper locking suggests a high severity risk of exploitation leading to denial of service or privilege escalation if the attacker can trigger the race.

Generated by OpenCVE AI on August 22, 2026 at 05:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that includes the commit sequence: 2ffb70a8a01988046bb207b7d0af9358a8337378, 4d8a2fe8847859f4fa4e9a2fa1221c9c1158e66b, 55e841836c6f4646490f7b0347192b7a92d431ba, or e94f92fd56c553a8bf9421c3289e1b85c7c08857, which introduce exclusive locking around net\-cells_dyn_ino modifications.
  • If a kernel upgrade is not immediately feasible, compile the suggested patches from the reference commits into your current kernel tree and rebuild the kernel.
  • Temporarily disable or restrict AFS filesystem usage (e.g., unmount AFS mounts or disable the AFS service) to minimize exposure until the lock fix is present in the kernel.

Generated by OpenCVE AI on August 22, 2026 at 05:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4745-1 linux-6.12 security update
History

Wed, 19 Aug 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-413
References
Metrics threat_severity

None

threat_severity

Moderate


Mon, 17 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Sat, 15 Aug 2026 11:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-362

Sat, 15 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: afs: Fix lack of locking around modifications of net->cells_dyn_ino Fix the lack of locking around modifications of net->cells_dyn_ino by taking net->cells_lock exclusively. This also requires to cell to be removed from net->cells_dyn_ino in afs_destroy_cell_work() rather than in afs_cell_destroy() as the latter runs in RCU cleanup context and sleeping locks cannot be taken there.
Title afs: Fix lack of locking around modifications of net->cells_dyn_ino
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-08-17T05:43:25.401Z

Reserved: 2026-08-09T03:40:39.922Z

Link: CVE-2026-72372

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-15T06:22:10.680

Modified: 2026-08-17T06:18:41.480

Link: CVE-2026-72372

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-08-15T00:00:00Z

Links: CVE-2026-72372 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-22T05:15:03Z

Weaknesses
  • CWE-362

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

  • CWE-413

    Improper Resource Locking