PT-2026-98523 · Linux · Linux Kernel

CVE-2026-97583

·

Published

2026-09-25

·

Updated

2026-09-25

CVSS v3.1

7.5

High

VectorAV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A slab-use-after-free issue exists in the AFS component of the Linux kernel. The function afs fs probe fileserver() fails to properly preserve the old address list when fetching the current endpoint state. This causes afs set peer appdata() to treat address list replacements as initial setups, failing to unbind peers removed from the old list. Consequently, an RxRPC connection may still pin a removed peer and attempt to call afs use server() on a freed object after the server destroyer and RCU callback have executed.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-97583

Affected Products

Linux Kernel