PT-2026-98523 · Linux · Linux Kernel
CVE-2026-97583
·
Published
2026-09-25
·
Updated
2026-09-25
CVSS v3.1
7.5
High
| Vector | AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A slab-use-after-free issue exists in the AFS component of the Linux kernel. The function
afs fs probe fileserver() fails to properly preserve the old address list when fetching the current endpoint state. This causes afs set peer appdata() to treat address list replacements as initial setups, failing to unbind peers removed from the old list. Consequently, an RxRPC connection may still pin a removed peer and attempt to call afs use server() on a freed object after the server destroyer and RCU callback have executed.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel