Answer in brief
CVE-2026-80877 records a Unknown severity vulnerability in afs: Fix vllist leak. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=d5c32c89b208e39a39cd8639aa21c012ce0daf4d <13403945c2385653e282dacda304dce2a25fdb53 || >=d5c32c89b208e39a39cd8639aa21c012ce0daf4d <2b169eedbb96f37f3f33d7b496d8283194988980 || >=d5c32c89b208e39a39cd8639aa21c012ce0daf4d <bf55969d9188380eb539bd216850bac27bc2e272 || >=d5c32c89b208e39a39cd8639aa21c012ce0daf4d <bef5514f6b6cb4bed9061f4b628d6be1cf26a39e || >=d5c32c89b208e39a39cd8639aa21c012ce0daf4d <fbfe75c81bff2359a03e85cf84293484cf60fcb9 || >=d5c32c89b208e39a39cd8639aa21c012ce0daf4d <8afb1a787a2802caf1895dd96745cfd6790a6f95 || >=d5c32c89b208e39a39cd8639aa21c012ce0daf4d <91d8f8e5fd34d3aed26f0fe6cf52b3f71de66cc6 || >=d5c32c89b208e39a39cd8639aa21c012ce0daf4d <fc10c0ecf06f2981af5d04357612b00051e03e9e | 13403945c2385653e282dacda304dce2a25fdb53, 2b169eedbb96f37f3f33d7b496d8283194988980, bf55969d9188380eb539bd216850bac27bc2e272, bef5514f6b6cb4bed9061f4b628d6be1cf26a39e, fbfe75c81bff2359a03e85cf84293484cf60fcb9, 8afb1a787a2802caf1895dd96745cfd6790a6f95, 91d8f8e5fd34d3aed26f0fe6cf52b3f71de66cc6, fc10c0ecf06f2981af5d04357612b00051e03e9e |
| Linux/Linuxgeneric | 5.2 | Not reported |
Published upstream
Sep 4, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 4, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 4, 2026
In the Linux kernel, the following vulnerability has been resolved: afs: Fix vllist leak Fix a leak of the new vllist in afs_update_cell() in the event that it is an empty list (nr_servers == 0), in which case the old list isn't displaced unless the old list is also empty.
Quoted source text, attributed separately from HOL analysis.