SB2026081532 - Improper resource shutdown or release in Linux kernel afs
Published: August 15, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Improper resource shutdown or release (CVE-ID: CVE-2026-74427)
CWE-ID: CWE-404 - Improper Resource Shutdown or Release
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper shutdown handling in the afs network namespace preallocation work logic when tearing down an afs network namespace. A local user can trigger network namespace teardown to cause a denial of service.
The issue involves cancellation and requeue behavior of the preallocated rxrpc call, connection, and peer charger while incoming calls are being disabled.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/47694fbc9d24ab6bf210f91e8efe06a10a478064
- https://git.kernel.org/stable/c/59e8b7652f6cbfb62d377ead0ad553c1b4e39a7a
- https://git.kernel.org/stable/c/63ccaf1bdf8be2330f47f9b5b233dd3fd04acbd9
- https://git.kernel.org/stable/c/85d5fb80fe4f0cc836b6df83f26de204fe102ff7
- https://git.kernel.org/stable/c/a33975ff2b6ea47b8f29956403374b1cdd057539
- https://git.kernel.org/stable/c/b83ecf80e28afb7b6595ba79932e77ca68a5a83d
- https://git.kernel.org/stable/c/eec89c5f8e1adc1de4824042ef75f62aed804153
- https://git.kernel.org/stable/c/f5096e18b6b7fbd1c2a1942e275a51bcfdfb2ad1