PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-72375 Linux CVE debrief

The CVE-2026-72375 vulnerability is related to the Andrew File System (afs) module in the Linux kernel. The issue arises from the insufficient initialization of work_structs in the slab's init function, specifically with the afs_vnode::lock_work. This leads to a warning from the DEBUG_OBJECTS debugging mechanism when running tests like generic/131 xfstest. The fix involves reinitializing ->lock_work after allocating an inode and flushing ->lock_work when the inode is being evicted. Linux kernel maintainers, users of the afs module, and administrators of systems running the affected kernel versions should be aware of this vulnerability and take necessary actions to patch their systems. The vulnerability has a significant impact on the Linux kernel, and users should prioritize assessment and patching of the affected systems.

Vendor
Linux
Product
Unknown
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-15
Original CVE updated
2026-08-15
Advisory published
2026-08-15
Advisory updated
2026-08-15

Who should care

Linux kernel maintainers, users of the afs module, and administrators of systems running the affected kernel versions should be aware of this vulnerability and take necessary actions to patch their systems. The vulnerability has a significant impact on the Linux kernel, and users should prioritize assessment and patching of the affected systems. Affected operator, platform, vulnerability-management, and security-team impact should be carefully evaluated to ensure proper mitigation.

Technical summary

The CVE-2026-72375 vulnerability is related to the Andrew File System (afs) module in the Linux kernel. The issue arises from the insufficient initialization of work_structs in the slab's init function, specifically with the afs_vnode::lock_work. This leads to a warning from the DEBUG_OBJECTS debugging mechanism when running tests like generic/131 xfstest. The fix involves reinitializing ->lock_work after allocating an inode and flushing ->lock_work when the inode is being evicted. The vulnerability has a significant impact on the Linux kernel, and users should prioritize assessment and patching of the affected systems.

Defensive priority

Linux kernel maintainers and users should prioritize assessment and patching of the affected systems.

Recommended defensive actions

  • Review and apply the provided patches to ensure the afs module is properly handling inode initialization and lock_work.
  • Run the generic/131 xfstest to verify the fix.
  • Monitor system logs for any signs of the DEBUG_OBJECTS warning.
  • Perform a thorough review of the affected systems to identify potential exposure.
  • Implement compensating controls for exposed systems while remediation is scheduled and verified.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Review relevant monitoring, detection, and logs for exposed assets that need extra review.

Evidence notes

The CVE is related to a vulnerability in the Linux kernel, specifically in the afs (Andrew File System) module. The issue is with the reinitialization of the inode's lock_work. The problem arises because initializing work_structs only once in the slab's init function is not sufficient. This results in a warning from the DEBUG_OBJECTS debugging mechanism when running certain tests.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-72375 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-72375

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-72375 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-72375

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/5597fbd1e7c161914f20315a726e54025b0fdadb

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/63d3f283858fae097fb09ddd4ce46bb0bc1f9d01

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/ebfd13c0367adb43d7c0a72f5cd7e004e60c6b28

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.