Answer in brief
CVE-2026-74426 records a Unknown severity vulnerability in afs: fix NULL pointer dereference in afs_get_tree(). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
Answer in brief
CVE-2026-74426 records a Unknown severity vulnerability in afs: fix NULL pointer dereference in afs_get_tree(). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=80548b03991f58758a336424a90bf9f988e3b077 <67fb48c4a0874953212321cd5d57fdb4900dbc31 || >=80548b03991f58758a336424a90bf9f988e3b077 <d648cc2069eb081707c061849046d909f57c78b1 || >=80548b03991f58758a336424a90bf9f988e3b077 <d5b17474feed3c30991f07affa2473adbad95055 || >=80548b03991f58758a336424a90bf9f988e3b077 <867b3ea146a041023bfcd258e6db516b1bb28f19 || >=80548b03991f58758a336424a90bf9f988e3b077 <ea19edf71721cd42f923e3c70f4ff995b422fe3b || >=80548b03991f58758a336424a90bf9f988e3b077 <23b3d457d8387bcb2a61063a9e520063ada9335f || >=80548b03991f58758a336424a90bf9f988e3b077 <70b2842734d831c908474779bb8a76daf55f782c || >=80548b03991f58758a336424a90bf9f988e3b077 <0b70716081c6462be9b2928ad736d0d527b09678 | 67fb48c4a0874953212321cd5d57fdb4900dbc31, d648cc2069eb081707c061849046d909f57c78b1, d5b17474feed3c30991f07affa2473adbad95055, 867b3ea146a041023bfcd258e6db516b1bb28f19, ea19edf71721cd42f923e3c70f4ff995b422fe3b, 23b3d457d8387bcb2a61063a9e520063ada9335f, 70b2842734d831c908474779bb8a76daf55f782c, 0b70716081c6462be9b2928ad736d0d527b09678 |
| Linux/Linuxgeneric | 5.2 | Not reported |
Published upstream
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 15, 2026
In the Linux kernel, the following vulnerability has been resolved: afs: fix NULL pointer dereference in afs_get_tree() afs_alloc_sbi() uses kzalloc for memory allocation. And, if ctx->dyn_root is not null, as->cell and as->volume are null. In trace_afs_get_tree() they are dereferenced. KASAN error message: KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007] CPU: 2 PID: 18478 Comm: syz-executor.7 Not tainted 5.10.246-syzkaller #0 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.12.0-1 04/01/2014 RIP: 0010:perf_trace_afs_get_tree+0x1d9/0x550 include/trace/events/afs.h:1365 Call Trace: trace_afs_get_tree include/trace/events/afs.h:1365 [inline] afs_get_tree+0x922/0x1350 fs/afs/super.c:599 vfs_get_tree+0x8e/0x300 fs/super.c:1572 do_new_mount fs/namespace.c:3011 [inline] path_mount+0x14a5/0x2220 fs/namespace.c:3341 do_mount fs/namespace.c:3354 [inline] __do_sys_mount fs/namespace.c:3562 [inline] __se_sys_mount fs/namespace.c:3539 [inline] __x64_sys_mount+0x283/0x300 fs/namespace.c:3539 do_syscall_64+0x33/0x50 arch/x86/entry/common.c:46 entry_SYSCALL_64_after_hwframe+0x67/0xd1 Found by Linux Verification Center (linuxtesting.org) with Syzkaller.
Quoted source text, attributed separately from HOL analysis.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=80548b03991f58758a336424a90bf9f988e3b077 <67fb48c4a0874953212321cd5d57fdb4900dbc31 || >=80548b03991f58758a336424a90bf9f988e3b077 <d648cc2069eb081707c061849046d909f57c78b1 || >=80548b03991f58758a336424a90bf9f988e3b077 <d5b17474feed3c30991f07affa2473adbad95055 || >=80548b03991f58758a336424a90bf9f988e3b077 <867b3ea146a041023bfcd258e6db516b1bb28f19 || >=80548b03991f58758a336424a90bf9f988e3b077 <ea19edf71721cd42f923e3c70f4ff995b422fe3b || >=80548b03991f58758a336424a90bf9f988e3b077 <23b3d457d8387bcb2a61063a9e520063ada9335f || >=80548b03991f58758a336424a90bf9f988e3b077 <70b2842734d831c908474779bb8a76daf55f782c || >=80548b03991f58758a336424a90bf9f988e3b077 <0b70716081c6462be9b2928ad736d0d527b09678 | 67fb48c4a0874953212321cd5d57fdb4900dbc31, d648cc2069eb081707c061849046d909f57c78b1, d5b17474feed3c30991f07affa2473adbad95055, 867b3ea146a041023bfcd258e6db516b1bb28f19, ea19edf71721cd42f923e3c70f4ff995b422fe3b, 23b3d457d8387bcb2a61063a9e520063ada9335f, 70b2842734d831c908474779bb8a76daf55f782c, 0b70716081c6462be9b2928ad736d0d527b09678 |
| Linux/Linuxgeneric | 5.2 | Not reported |
Published upstream
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 15, 2026
In the Linux kernel, the following vulnerability has been resolved: afs: fix NULL pointer dereference in afs_get_tree() afs_alloc_sbi() uses kzalloc for memory allocation. And, if ctx->dyn_root is not null, as->cell and as->volume are null. In trace_afs_get_tree() they are dereferenced. KASAN error message: KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007] CPU: 2 PID: 18478 Comm: syz-executor.7 Not tainted 5.10.246-syzkaller #0 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.12.0-1 04/01/2014 RIP: 0010:perf_trace_afs_get_tree+0x1d9/0x550 include/trace/events/afs.h:1365 Call Trace: trace_afs_get_tree include/trace/events/afs.h:1365 [inline] afs_get_tree+0x922/0x1350 fs/afs/super.c:599 vfs_get_tree+0x8e/0x300 fs/super.c:1572 do_new_mount fs/namespace.c:3011 [inline] path_mount+0x14a5/0x2220 fs/namespace.c:3341 do_mount fs/namespace.c:3354 [inline] __do_sys_mount fs/namespace.c:3562 [inline] __se_sys_mount fs/namespace.c:3539 [inline] __x64_sys_mount+0x283/0x300 fs/namespace.c:3539 do_syscall_64+0x33/0x50 arch/x86/entry/common.c:46 entry_SYSCALL_64_after_hwframe+0x67/0xd1 Found by Linux Verification Center (linuxtesting.org) with Syzkaller.
Quoted source text, attributed separately from HOL analysis.