PatchSiren cyber security CVE debrief
CVE-2026-72375 Linux CVE debrief
The CVE-2026-72375 vulnerability is related to the Andrew File System (afs) module in the Linux kernel. The issue arises from the insufficient initialization of work_structs in the slab's init function, specifically with the afs_vnode::lock_work. This leads to a warning from the DEBUG_OBJECTS debugging mechanism when running tests like generic/131 xfstest. The fix involves reinitializing ->lock_work after allocating an inode and flushing ->lock_work when the inode is being evicted. Linux kernel maintainers, users of the afs module, and administrators of systems running the affected kernel versions should be aware of this vulnerability and take necessary actions to patch their systems. The vulnerability has a significant impact on the Linux kernel, and users should prioritize assessment and patching of the affected systems.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-15
- Original CVE updated
- 2026-08-15
- Advisory published
- 2026-08-15
- Advisory updated
- 2026-08-15
Who should care
Linux kernel maintainers, users of the afs module, and administrators of systems running the affected kernel versions should be aware of this vulnerability and take necessary actions to patch their systems. The vulnerability has a significant impact on the Linux kernel, and users should prioritize assessment and patching of the affected systems. Affected operator, platform, vulnerability-management, and security-team impact should be carefully evaluated to ensure proper mitigation.
Technical summary
The CVE-2026-72375 vulnerability is related to the Andrew File System (afs) module in the Linux kernel. The issue arises from the insufficient initialization of work_structs in the slab's init function, specifically with the afs_vnode::lock_work. This leads to a warning from the DEBUG_OBJECTS debugging mechanism when running tests like generic/131 xfstest. The fix involves reinitializing ->lock_work after allocating an inode and flushing ->lock_work when the inode is being evicted. The vulnerability has a significant impact on the Linux kernel, and users should prioritize assessment and patching of the affected systems.
Defensive priority
Linux kernel maintainers and users should prioritize assessment and patching of the affected systems.
Recommended defensive actions
- Review and apply the provided patches to ensure the afs module is properly handling inode initialization and lock_work.
- Run the generic/131 xfstest to verify the fix.
- Monitor system logs for any signs of the DEBUG_OBJECTS warning.
- Perform a thorough review of the affected systems to identify potential exposure.
- Implement compensating controls for exposed systems while remediation is scheduled and verified.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
- Review relevant monitoring, detection, and logs for exposed assets that need extra review.
Evidence notes
The CVE is related to a vulnerability in the Linux kernel, specifically in the afs (Andrew File System) module. The issue is with the reinitialization of the inode's lock_work. The problem arises because initializing work_structs only once in the slab's init function is not sufficient. This results in a warning from the DEBUG_OBJECTS debugging mechanism when running certain tests.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-72375 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-72375
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-72375 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-72375
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/5597fbd1e7c161914f20315a726e54025b0fdadb
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/63d3f283858fae097fb09ddd4ce46bb0bc1f9d01
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/ebfd13c0367adb43d7c0a72f5cd7e004e60c6b28
416baaa9-dc9f-4396-8d5f-8c081fb06d67
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.