CVE-2026-74728

Source
https://cve.org/CVERecord?id=CVE-2026-74728
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74728.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-74728
Downstream
Published
2026-08-22T15:33:18Z
Modified
2026-08-24T11:47:22Z
Summary
xfs: handle NULL b_addr in xfs_buf_free
Details

In the Linux kernel, the following vulnerability has been resolved:

xfs: handle NULL b_addr in xfs_buf_free

When xfs_buf_alloc_backing_mem() fails, xfs_buf_free() is called with bp->b_addr still NULL. The code falls through to the folio_put path which calls virt_to_folio(NULL), dereferencing an invalid address and causing a kernel crash.

Call Trace: xfs_buf_free+0x25f/0x510 xfs_buf_alloc+0xc98/0x19b0 xfs_buf_find_insert+0x55/0x14d0 xfs_buf_get_map+0x122b/0x17c0 xfbtree_init_leaf_block+0x11c/0x4a0 xfbtree_init+0x1bb/0x460 xrep_rmap_setup_scan+0x100/0x1f0 xrep_rmapbt+0x41/0xc0

Fix this by skipping folio_put() when bp->b_addr is NULL.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/74xxx/CVE-2026-74728.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
5076a6040ca1613e616d84aecfaac5f932db84e0
Fixed
ccf6738adcafa5ddbddc4e71b45d8a51b86643c7
Fixed
3aa0c1d23ee1b9d9b340fb2f4736536e1408d706
Fixed
d852729c5f4f830fbe7413df032e29459b3daf83

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74728.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.9.0
Fixed
6.18.45
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74728.json"