Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-97583— afs: Clear stale peer app data after address list changes

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Linux 内核中,以下漏洞已得到修复: afs: 在地址列表变更后清除过期的对等节点应用数据 函数在持有 锁的情况下获取当前的端点状态,但未将 设置为 NULL。因此, 函数会将每一次地址列表的替换都视为初始设置,仅绑定新的对等节点(peers),而从未解绑已从旧列表中移除的对等节点。 因此,地址刷新过程可能发生如下情况:CPU 0 替换服务器 S 的地址列表,丢弃了旧的对等节点 Pold,但未清除 。随后,服务器销毁器仅清除了 S 当前的对等节点,并允许 S 进入 RCU 回调阶段。在回调完成并释放 S 之

CVSS 7.5 · High EPSS 0.41% · P33

Possible ATT&CK Techniques 1 AI

T1135 · Network Share Discovery

Affected Version Matrix 11

VendorProduct Version RangeStatus
Linux Linux 39ba6af83a7f9dee3e6a7916f41a48bcbda54eba< 3afb988fd0411707bdafb9b321086fff0da28aae affected
40e8b52fe8c8ab6920ea5f59c5469b6918cce624< c7f77a11a1e719192c7262aad38a3919aec62c21 affected
40e8b52fe8c8ab6920ea5f59c5469b6918cce624< 7f7f5589d048821dea316cbac9b37d27eaf7530e affected
40e8b52fe8c8ab6920ea5f59c5469b6918cce624< ba0623fc19a424f4745394c499f9f28a8d88d397 affected
6.12.101< 6.12.111 affected
6.15 affected
< 6.15 unaffected
6.12.111≤ 6.12.* unaffected
… +3 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-97583

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
afs: Clear stale peer app data after address list changes
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: afs: Clear stale peer app data after address list changes afs_fs_probe_fileserver() fetches the current endpoint state under server->fs_lock, but leaves old_alist as NULL. Consequently, afs_set_peer_appdata() treats every address list replacement as initial setup and only binds the new peers; it never unbinds peers removed from the old list. An address refresh can therefore proceed as follows. CPU 0 replaces server S's list and drops Pold without clearing Pold->app_data. The server destroyer then clears only S's current peers and lets S reach its RCU callback. After the callback frees S, CPU 1 handles a callback through an RxRPC connection that still pins Pold, reads Pold->app_data, and calls afs_use_server() on the freed object. KASAN reported: BUG: KASAN: slab-use-after-free in afs_find_server+0x3c/0xa0 Read of size 4 at addr ffff8881013e1af0 by task krxrpcio/7001/74 Call Trace: afs_find_server+0x3c/0xa0 afs_rx_new_call+0x15c/0x390 rxrpc_new_incoming_call+0x97c/0x1730 rxrpc_input_packet.constprop.0+0xd03/0xec0 rxrpc_io_thread+0x967/0x1640 Allocated by task 93: afs_lookup_server+0x1a7/0x14c0 afs_alloc_server_list+0x43f/0xb60 afs_create_volume+0x923/0x1490 afs_get_tree+0x1c6/0x10a0 Freed by task 0: kfree+0x131/0x3c0 rcu_core+0x50a/0x1850 Last potentially related work creation: __call_rcu_common.constprop.0+0x71/0xa10 afs_put_server+0x213/0x2b0 Preserve old->addresses for the peer app-data update so that removed peers are cleared before the endpoint state is replaced. Also advance both cursors when the old and new lists share a peer; activating the old/new comparison without this would otherwise loop forever on the shared entry.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux 39ba6af83a7f9dee3e6a7916f41a48bcbda54eba ~ 3afb988fd0411707bdafb9b321086fff0da28aae -
Linux Linux 6.15 -

II. Public POCs for CVE-2026-97583

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-97583

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-97583 (4)

Same Patch Batch · Linux · 2026-09-25 · 372 CVEs total

CVE-2026-100075 9.8 CRITICAL RDMA/srpt: Fix srpt_alloc_rw_ctxs() unwind counters
CVE-2026-97957 8.8 HIGH net: hinic: fix mailbox segment buffer overflow
CVE-2026-97527 8.8 HIGH scsi: qla2xxx: Serialize NVMe unsol ctx list with a per-fcport lock
CVE-2026-97528 8.8 HIGH scsi: qla2xxx: Unlink NVMe unsol ctx before freeing on LS reject error
CVE-2026-97555 8.8 HIGH smb: client: fix heap overflow in DACL owner/group rewrite
CVE-2026-98115 8.8 HIGH ksmbd: safely drain sessions during logoff
CVE-2026-97525 8.2 HIGH x86/mm/pat: Allocate split page tables as kernel page tables
CVE-2026-98130 8.1 HIGH sctp: fix a TOCTOU race in SCTP_CMD_TIMER_START
CVE-2026-97573 8.1 HIGH bnxt_en: Handle buffer allocation failure in bnxt_rx_ring_reset()
CVE-2026-98069 8.1 HIGH net/rds: acquire the fastpath locks in rds_conn_shutdown()
CVE-2026-98070 8.1 HIGH net/rds: acquire RDS_IN_XMIT in rds_tcp_reset_callbacks()
CVE-2026-97570 8.1 HIGH bnxt_en: Bound SW TPA IDs to prevent crashes
CVE-2026-97911 7.8 HIGH accel: ethosu: Ensure SRAM region size matches job
CVE-2026-98023 7.8 HIGH vxlan: reject dynamic fdb entries that reference a nexthop id
CVE-2026-97910 7.8 HIGH ASoC: sprd: validate compress buffer sizes against fixed allocations
CVE-2026-97584 7.8 HIGH afs: Fix incorrect free in candidate cleanup in afs_lookup_server()
CVE-2026-98143 7.8 HIGH accel: ethosu: Don't read the U65 rounding mode as a storage mode
CVE-2026-97903 7.8 HIGH exit: hold a reference to thread_pid across proc_flush_pid
CVE-2026-97548 7.8 HIGH xfs: fix the rtrmap and rtrefcount _maxlevels_ondisk functions
CVE-2026-97594 7.8 HIGH landlock: Fix use-after-free of the source's parent directory

Showing top 20 of 372 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-97583

No comments yet


Leave a comment