{"apiVersion":"1.0","identifier":"CVE-2026-72377","description":"In the Linux kernel, the following vulnerability has been resolved: afs: Remove setting of AS_RELEASE_ALWAYS for symlinks and mountpoints Regular AFS files correctly use afs_file_aops which have release_folio set as netfs_release_folio, so AS_RELEASE_ALWAYS is valid for them when fscache is enabled (set via afs_vnode_set_cache()). Symlinks and mountpoints in AFS use afs_dir_aops, which does not provide a release_folio callback. However, afs_apply_status() unconditionally calls mapping_set_release_always() for these. In such case when memory management code attempts to release folios, filemap_release_folio() checks folio_needs_release() which returns true due to AS_RELEASE_ALWAYS being set. Since there is no release_folio callback, it falls through to try_to_free_buffers(), which at present expects buffer_heads to be not null. For symlinks and mountpoints without buffer_heads, this causes pointer dereference. [dh: Added more bits that were missed]","publishedAt":"2026-08-15T06:22:11","lastModifiedAt":"2026-08-17T06:18:42","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-72377","cvssScore":null,"cvssVector":"Pending","epssProbability":0.00198,"riskScore":0,"affectedProduct":"Linux kernel","affectedVersions":"unknown","vulnerabilityType":"Kernel","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-72377","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-72377","en":"https://www.redsauce.net/en/cves/CVE-2026-72377","fr":"https://www.redsauce.net/fr/cves/CVE-2026-72377","pt":"https://www.redsauce.net/pt/cves/CVE-2026-72377","de":"https://www.redsauce.net/de/cves/CVE-2026-72377","sk":"https://www.redsauce.net/sk/cves/CVE-2026-72377","el":"https://www.redsauce.net/el/cves/CVE-2026-72377"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-72377"}}