Answer in brief
CVE-2026-72374 records a Unknown severity vulnerability in afs: Fix callback service message parsers to pass through -EAGAIN. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
Answer in brief
CVE-2026-72374 records a Unknown severity vulnerability in afs: Fix callback service message parsers to pass through -EAGAIN. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=d001648ec7cf8b21ae9eec8b9ba4a18295adfb14 <26b737b3769e92493fe94c34620399d93ca231ae || >=d001648ec7cf8b21ae9eec8b9ba4a18295adfb14 <09c67a7ded481482155b836c8c7f078a3075f8de || >=d001648ec7cf8b21ae9eec8b9ba4a18295adfb14 <239cd337c9d047e7097f5b2ebbb41ddfb8180bc6 || >=d001648ec7cf8b21ae9eec8b9ba4a18295adfb14 <5a39b145a8fb49f316e7ec1f29ba51d68095c7e4 || >=d001648ec7cf8b21ae9eec8b9ba4a18295adfb14 <772850871a2e772e26f9d93f1e9ddd413b3eeaa4 || >=d001648ec7cf8b21ae9eec8b9ba4a18295adfb14 <0acbc09d2aca0432af45cec114f20d55ceafaec4 || >=d001648ec7cf8b21ae9eec8b9ba4a18295adfb14 <f14dd036fad3d359f26f1282199cec06b3a9362b || >=d001648ec7cf8b21ae9eec8b9ba4a18295adfb14 <0f36469d7ce98b362934113c550d08bb0c784231 | 26b737b3769e92493fe94c34620399d93ca231ae, 09c67a7ded481482155b836c8c7f078a3075f8de, 239cd337c9d047e7097f5b2ebbb41ddfb8180bc6, 5a39b145a8fb49f316e7ec1f29ba51d68095c7e4, 772850871a2e772e26f9d93f1e9ddd413b3eeaa4, 0acbc09d2aca0432af45cec114f20d55ceafaec4, f14dd036fad3d359f26f1282199cec06b3a9362b, 0f36469d7ce98b362934113c550d08bb0c784231 |
| Linux/Linuxgeneric | 4.9 | Not reported |
Published upstream
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 15, 2026
In the Linux kernel, the following vulnerability has been resolved: afs: Fix callback service message parsers to pass through -EAGAIN The AFS filesystem client uses an rxrpc server to listen for callback notifications. Each callback call type handler has a delivery function that parses the incoming request stream, and this should return -EAGAIN the last packet hasn't yet been seen, but all currently queued received data is consumed. afs_extract_data() does this, but the -EAGAIN return is switched to 0 inadvertantly Fix callback service message parsers to pass through -EAGAIN
Quoted source text, attributed separately from HOL analysis.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=d001648ec7cf8b21ae9eec8b9ba4a18295adfb14 <26b737b3769e92493fe94c34620399d93ca231ae || >=d001648ec7cf8b21ae9eec8b9ba4a18295adfb14 <09c67a7ded481482155b836c8c7f078a3075f8de || >=d001648ec7cf8b21ae9eec8b9ba4a18295adfb14 <239cd337c9d047e7097f5b2ebbb41ddfb8180bc6 || >=d001648ec7cf8b21ae9eec8b9ba4a18295adfb14 <5a39b145a8fb49f316e7ec1f29ba51d68095c7e4 || >=d001648ec7cf8b21ae9eec8b9ba4a18295adfb14 <772850871a2e772e26f9d93f1e9ddd413b3eeaa4 || >=d001648ec7cf8b21ae9eec8b9ba4a18295adfb14 <0acbc09d2aca0432af45cec114f20d55ceafaec4 || >=d001648ec7cf8b21ae9eec8b9ba4a18295adfb14 <f14dd036fad3d359f26f1282199cec06b3a9362b || >=d001648ec7cf8b21ae9eec8b9ba4a18295adfb14 <0f36469d7ce98b362934113c550d08bb0c784231 | 26b737b3769e92493fe94c34620399d93ca231ae, 09c67a7ded481482155b836c8c7f078a3075f8de, 239cd337c9d047e7097f5b2ebbb41ddfb8180bc6, 5a39b145a8fb49f316e7ec1f29ba51d68095c7e4, 772850871a2e772e26f9d93f1e9ddd413b3eeaa4, 0acbc09d2aca0432af45cec114f20d55ceafaec4, f14dd036fad3d359f26f1282199cec06b3a9362b, 0f36469d7ce98b362934113c550d08bb0c784231 |
| Linux/Linuxgeneric | 4.9 | Not reported |
Published upstream
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 15, 2026
In the Linux kernel, the following vulnerability has been resolved: afs: Fix callback service message parsers to pass through -EAGAIN The AFS filesystem client uses an rxrpc server to listen for callback notifications. Each callback call type handler has a delivery function that parses the incoming request stream, and this should return -EAGAIN the last packet hasn't yet been seen, but all currently queued received data is consumed. afs_extract_data() does this, but the -EAGAIN return is switched to 0 inadvertantly Fix callback service message parsers to pass through -EAGAIN
Quoted source text, attributed separately from HOL analysis.