In the Linux kernel, the following vulnerability has been resolved:
afs: Fix dynamic root getattr
The recent patch to make afs_getattr consult the server didn't account for the pseudo-inodes employed by the dynamic root-type afs superblock not having a volume or a server to access, and thus an oops occurs if such a directory is stat'd.
Fix this by checking to see if the vnode->volume pointer actually points anywhere before following it in afs_getattr().
This can be tested by stat'ing a directory in /afs. It may be sufficient just to do "ls /afs" and the oops looks something like:
BUG: kernel NULL pointer dereference, address: 0000000000000020 ... RIP: 0010:afs_getattr+0x8b/0x14b ... Call Trace: <TASK> vfs_statx+0x79/0xf5 vfs_fstatat+0x49/0x62
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade kernelUpgrade python-perf-debuginfoUpgrade kernel-tools-develUpgrade kernel-headersUpgrade perf-debuginfoUpgrade kernel-livepatch-5.10.130-118.517Upgrade perfUpgrade kernel-debuginfo-common-aarch64Upgrade kernel-develUpgrade python-perfUpgrade bpftool-debuginfoUpgrade kernel-tools-debuginfoUpgrade kernel-debuginfo-common-x86_64Upgrade kernel-toolsUpgrade kernel-livepatch-5.15.54-25.126Upgrade bpftoolUpgrade kernel-debuginfo | May 22, 2025 | Feb 26, 2025 |
| Debian | — | Upgrade linux | Feb 27, 2025 | Feb 27, 2025 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Feb 26, 2025 |
| Ubuntu | — | Upgrade linux-awsUpgrade linux-aws-hweUpgrade linux-hweUpgrade linux-gcp-5.15Upgrade linux-intel-iotg-5.15Upgrade linux-realtimeUpgrade linux-kvmUpgrade linux-oracle-5.15Upgrade linux-gcp-4.15Upgrade linux-azureUpgrade linux-ibmUpgrade linux-raspiUpgrade linux-lowlatencyUpgrade linux-oracleUpgrade linux-azure-4.15Upgrade linux-aws-5.15Upgrade linux-gcp-fipsUpgrade linux-gkeUpgrade linux-intel-iotgUpgrade linuxUpgrade linux-aws-fipsUpgrade linux-azure-5.15Upgrade linux-gkeopUpgrade linux-gcpUpgrade linux-fipsUpgrade linux-riscv-5.15Upgrade linux-azure-fips | Mar 3, 2025 | Feb 26, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub