CVE-2026-72377

In the Linux kernel, the following vulnerability has been resolved: afs: Remove setting of AS_RELEASE_ALWAYS for symlinks and mountpoints Regular AFS files correctly use afs_file_aops which have release_folio set as netfs_release_folio, so AS_RELEASE_ALWAYS is valid for them when fscache is enabled (set via afs_vnode_set_cache()). Symlinks and mountpoints in AFS use afs_dir_aops, which does not provide a release_folio callback. However, afs_apply_status() unconditionally calls mapping_set_release_always() for these. In such case when memory management code attempts to release folios, filemap_release_folio() checks folio_needs_release() which returns true due to AS_RELEASE_ALWAYS being set. Since there is no release_folio callback, it falls through to try_to_free_buffers(), which at present expects buffer_heads to be not null. For symlinks and mountpoints without buffer_heads, this causes pointer dereference. [dh: Added more bits that were missed]

Package Linux Kernel
Published 2026-08-15
Last modified 2026-08-17
Patch available
Yes

Affected versions

Linux kernel versions 6.14 and later are affected. Fixed in 7.1.5, 7.2 and their respective stable series.

Affected from
≥ 6.14
Fixed in
✓ 7.1.5 7.1.x ✓ 7.2

Frequently asked questions

  • What is CVE-2026-72377?

    CVE-2026-72377 is a unscored severity Linux kernel vulnerability . It affects Linux kernel versions from 6.14 onward and has been patched in 7.1.5 and 7.2. CVE-2026-72377 has not been confirmed as actively exploited and is not listed in the CISA KEV catalog.

  • Is there a patch available for CVE-2026-72377?

    Yes. CVE-2026-72377 has been patched. Fixed versions include 7.1.5 and 7.2. If you are running Linux kernel 6.14 or later up to the fix versions, apply the relevant patch for your kernel branch.

  • Is CVE-2026-72377 actively exploited?

    No. CVE-2026-72377 has not been confirmed as actively exploited. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.