CVE-2026-72371
In the Linux kernel, the following vulnerability has been resolved: afs: Fix the volume AFS_VOLUME_RM_TREE is set on Fix afs_insert_volume_into_cell() to set AFS_VOLUME_RM_TREE on the volume replaced, not the new volume, as it's now removed from the…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.18%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
In the Linux kernel, the following vulnerability has been resolved: afs: Fix the volume AFS_VOLUME_RM_TREE is set on Fix afs_insert_volume_into_cell() to set AFS_VOLUME_RM_TREE on the volume replaced, not the new volume, as it's now removed from the cell's volume tree. This will cause the old volume to be removed from the tree twice and the new volume never to be removed.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.18% probability · 7th percentile
- CISA KEV
- Not listed
- Source
- 416baaa9-dc9f-4396-8d5f-8c081fb06d67
References
- https://git.kernel.org/stable/c/158c5a0b1dfc0e6a419efe18404047a4d2dff59e
- https://git.kernel.org/stable/c/1607075220cf57161d9116512994c159eacefc0d
- https://git.kernel.org/stable/c/56b4e4b26f84411d880f968a539207b0a8889c8c
- https://git.kernel.org/stable/c/6fa9a8a73e16aa22fce6e41cc00d59c767f0a540
- https://git.kernel.org/stable/c/c421bc6b957e56e45e12dbaeaf70a60db20d6465
- https://git.kernel.org/stable/c/d0c8ad418b47891a03426c5e02ebb0537f8d68f8
- https://git.kernel.org/stable/c/d154c20837f379343f192d4b8d9dd4ef145562e6
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.