Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-97583

Gravedad CVSS v3.1:
ALTA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
25/09/2026
Última modificación:
25/09/2026

Descripción

*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> afs: Clear stale peer app data after address list changes<br /> <br /> afs_fs_probe_fileserver() fetches the current endpoint state under<br /> server-&gt;fs_lock, but leaves old_alist as NULL. Consequently,<br /> afs_set_peer_appdata() treats every address list replacement as initial<br /> setup and only binds the new peers; it never unbinds peers removed from<br /> the old list.<br /> <br /> An address refresh can therefore proceed as follows. CPU 0 replaces<br /> server S&amp;#39;s list and drops Pold without clearing Pold-&gt;app_data. The<br /> server destroyer then clears only S&amp;#39;s current peers and lets S reach its<br /> RCU callback. After the callback frees S, CPU 1 handles a callback<br /> through an RxRPC connection that still pins Pold, reads Pold-&gt;app_data,<br /> and calls afs_use_server() on the freed object.<br /> <br /> KASAN reported:<br /> <br /> BUG: KASAN: slab-use-after-free in afs_find_server+0x3c/0xa0<br /> Read of size 4 at addr ffff8881013e1af0 by task krxrpcio/7001/74<br /> Call Trace:<br /> afs_find_server+0x3c/0xa0<br /> afs_rx_new_call+0x15c/0x390<br /> rxrpc_new_incoming_call+0x97c/0x1730<br /> rxrpc_input_packet.constprop.0+0xd03/0xec0<br /> rxrpc_io_thread+0x967/0x1640<br /> Allocated by task 93:<br /> afs_lookup_server+0x1a7/0x14c0<br /> afs_alloc_server_list+0x43f/0xb60<br /> afs_create_volume+0x923/0x1490<br /> afs_get_tree+0x1c6/0x10a0<br /> Freed by task 0:<br /> kfree+0x131/0x3c0<br /> rcu_core+0x50a/0x1850<br /> Last potentially related work creation:<br /> __call_rcu_common.constprop.0+0x71/0xa10<br /> afs_put_server+0x213/0x2b0<br /> <br /> Preserve old-&gt;addresses for the peer app-data update so that removed<br /> peers are cleared before the endpoint state is replaced. Also advance<br /> both cursors when the old and new lists share a peer; activating the<br /> old/new comparison without this would otherwise loop forever on the<br /> shared entry.