CVE-2026-72371
Published: August 18, 2026Last modified: August 18, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: afs: Fix the volume AFS_VOLUME_RM_TREE is set on Fix afs_insert_volume_into_cell() to set AFS_VOLUME_RM_TREE on the volume replaced, not the new volume, as it's now removed from the cell's volume tree. This will cause the old volume to be removed from the tree twice and the new volume never to be removed.
Severity score breakdown
| Parameter | Value |
|---|---|
| Base score | 7.8 |
| Attack Vector | LOCAL |
| Attack complexity | LOW |
| Privileges required | LOW |
| User interaction | NONE |
| Scope | UNCHANGED |
| Confidentiality | HIGH |
| Integrity impact | HIGH |
| Availability impact | HIGH |
| Vector | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Status
| Product | Release | Package | Status |
|---|---|---|---|
| Alpaquita Linux | 23 LTS | linux-lts | Fixed (6.1.182-r0) |
| 25 LTS | linux-lts | Fixed (6.12.103-r0) | |
| Stream | linux-lts | Fixed (6.18.43-r0) |
References
- https://git.kernel.org/stable/c/158c5a0b1dfc0e6a419efe18404047a4d2dff59e
- https://git.kernel.org/stable/c/1607075220cf57161d9116512994c159eacefc0d
- https://git.kernel.org/stable/c/56b4e4b26f84411d880f968a539207b0a8889c8c
- https://git.kernel.org/stable/c/6fa9a8a73e16aa22fce6e41cc00d59c767f0a540
- https://git.kernel.org/stable/c/c421bc6b957e56e45e12dbaeaf70a60db20d6465
- https://git.kernel.org/stable/c/d0c8ad418b47891a03426c5e02ebb0537f8d68f8
- https://git.kernel.org/stable/c/d154c20837f379343f192d4b8d9dd4ef145562e6