CVE-2026-72375
Received Received - Intake

Linux Kernel AFS Inode Lock Work Reinitialization Flaw

Vulnerability report for CVE-2026-72375, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-15

Last updated on: 2026-08-17

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: afs: Fix reinitialisation of the inode, in particular ->lock_work It seems that initalising afs_vnode::lock_work a single time in the slab's init function isn't sufficient for work_structs. This results in the DEBUG_OBJECTS debugging stuff producing a warning occasionally when running the generic/131 xfstest: ODEBUG: activate not available (active state 0) object: 0000000016d8760f object type: work_struct hint: afs_lock_work+0x0/0x220 WARNING: lib/debugobjects.c:629 at debug_print_object+0x4b/0x90, CPU#3: locktest/7695 ... CPU: 3 UID: 0 PID: 7695 Comm: locktest Tainted: G S 7.1.0-build3+ #2771 PREEMPT ... RIP: 0010:debug_print_object+0x65/0x90 ... Call Trace: <TASK> ? __pfx_afs_lock_work+0x10/0x10 debug_object_activate+0x122/0x170 insert_work+0x25/0x60 __queue_work+0x2e0/0x340 queue_delayed_work_on+0x48/0x70 afs_fl_release_private+0x57/0x70 locks_release_private+0x5c/0xa0 locks_free_lock+0xe/0x20 posix_lock_inode+0x55f/0x5b0 locks_lock_inode_wait+0x81/0x140 ? file_write_and_wait_range+0x50/0x70 afs_lock+0xcd/0x110 fcntl_setlk+0x10d/0x260 do_fcntl+0x24e/0x5b0 __do_sys_fcntl+0x6a/0x90 do_syscall_64+0x11e/0x310 entry_SYSCALL_64_after_hwframe+0x71/0x79 Fix this by reinitialising ->lock_work after allocating an inode. Also, flush ->lock_work when the inode is being evicted to make sure it's not still running.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-15
Last Modified
2026-08-17
Generated
2026-09-04
AI Q&A
2026-08-15
EPSS Evaluated
2026-09-03
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
linux linux_kernel From 7.1.0-build3+ (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Linux kernel involves improper initialization of the afs_vnode::lock_work field. The issue occurs because initializing this field once during slab initialization is insufficient for work_structs, leading to occasional warnings from the DEBUG_OBJECTS debugging system during xfstest execution.

Detection Guidance

This vulnerability is specific to the Linux kernel's AFS (Andrew File System) module and may trigger debug warnings during filesystem operations. Detection involves checking kernel logs for DEBUG_OBJECTS warnings related to work_structs in afs_lock_work. Monitor logs with: dmesg | grep -i 'DEBUG_OBJECTS\|afs_lock_work' or journalctl -k | grep -i 'DEBUG_OBJECTS\|afs_lock_work'.

Impact Analysis

This vulnerability may cause system instability or warnings during filesystem operations, particularly when using AFS (Andrew File System). It could lead to unexpected behavior in file locking operations or kernel debug warnings, though it does not appear to cause direct security compromise.

Compliance Impact

This vulnerability does not directly affect compliance with GDPR or HIPAA as it pertains to a Linux kernel issue involving inode initialization and work queue management. No evidence suggests it impacts data protection or privacy requirements.

Mitigation Strategies

Apply the kernel patch that reinitializes afs_vnode::lock_work after inode allocation and flushes it during inode eviction. Update to a kernel version containing the fix or backport the patch manually. Reboot the system after applying the update.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-72375. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart