PT-2026-72861 · Linux · Linux Kernel

CVE-2026-74425

·

Published

2026-08-15

·

Updated

2026-08-18

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the AFS (Andrew File System) component where the cache manager callback path fails to properly handle requests when a server record is not attached to an incoming call via the rxrpc peer's app data. Specifically, the CB.InitCallBackState3 handler does not verify the existence of the server record before use, which deviates from the behavior of other callback handlers that tolerate missing server records. This can lead to instability when the handler depends on peer state that is unavailable for a given request.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-74425

Affected Products

Linux Kernel