Null Pointer Dereference Vulnerability in Linux Kernel AFS Module
CVE-2026-74426

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
15 August 2026

What is CVE-2026-74426?

A vulnerability exists in the AFS module of the Linux kernel that may lead to a null pointer dereference. This occurs when a memory allocation failure is not adequately handled, resulting in dereferencing null pointers. Such issues can compromise system integrity and stability. The error, identified during testing, specifically happens in the afs_get_tree() function, where dereferencing occurs if certain context variables are null. This vulnerability was discovered by the Linux Verification Center using Syzkaller, highlighting the need for proactive fixes to maintain system reliability.

Affected Version(s)

Linux 80548b03991f58758a336424a90bf9f988e3b077 < 67fb48c4a0874953212321cd5d57fdb4900dbc31

Linux 80548b03991f58758a336424a90bf9f988e3b077

Linux 80548b03991f58758a336424a90bf9f988e3b077

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.