CVE-2026-74426

Source
https://cve.org/CVERecord?id=CVE-2026-74426
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74426.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-74426
Downstream
Published
2026-08-15T05:59:28.427Z
Modified
2026-08-16T03:48:35.265981245Z
Summary
afs: fix NULL pointer dereference in afs_get_tree()
Details

In the Linux kernel, the following vulnerability has been resolved:

afs: fix NULL pointer dereference in afsgettree()

afsallocsbi() uses kzalloc for memory allocation. And, if ctx->dynroot is not null, as->cell and as->volume are null. In traceafsgettree() they are dereferenced.

KASAN error message:

KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007] CPU: 2 PID: 18478 Comm: syz-executor.7 Not tainted 5.10.246-syzkaller #0 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.12.0-1 04/01/2014 RIP: 0010:perftraceafsgettree+0x1d9/0x550 include/trace/events/afs.h:1365

Call Trace: traceafsgettree include/trace/events/afs.h:1365 [inline] afsgettree+0x922/0x1350 fs/afs/super.c:599 vfsgettree+0x8e/0x300 fs/super.c:1572 donewmount fs/namespace.c:3011 [inline] pathmount+0x14a5/0x2220 fs/namespace.c:3341 do_mount fs/namespace.c:3354 [inline] __dosysmount fs/namespace.c:3562 [inline] __sesysmount fs/namespace.c:3539 [inline] __x64sysmount+0x283/0x300 fs/namespace.c:3539 dosyscall64+0x33/0x50 arch/x86/entry/common.c:46 entrySYSCALL64afterhwframe+0x67/0xd1

Found by Linux Verification Center (linuxtesting.org) with Syzkaller.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/74xxx/CVE-2026-74426.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
80548b03991f58758a336424a90bf9f988e3b077
Fixed
67fb48c4a0874953212321cd5d57fdb4900dbc31
Fixed
d648cc2069eb081707c061849046d909f57c78b1
Fixed
d5b17474feed3c30991f07affa2473adbad95055
Fixed
867b3ea146a041023bfcd258e6db516b1bb28f19
Fixed
ea19edf71721cd42f923e3c70f4ff995b422fe3b
Fixed
23b3d457d8387bcb2a61063a9e520063ada9335f
Fixed
70b2842734d831c908474779bb8a76daf55f782c
Fixed
0b70716081c6462be9b2928ad736d0d527b09678

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74426.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.2.0
Fixed
5.10.261
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.212
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.178
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.145
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.97
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.40
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74426.json"