Status: UPDATED | Advisory ID: CVE-2026-97584
| CVE | CVE-2026-97584 |
| CVSS Score / Version | 7.8 (High) / CVSS v3.1 |
| Updated | 2026-09-25 |
| CVSS Vector | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| CVSS Prose | attack vector is local; attack complexity is low; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high. |
| Affected products | Linux Linux |
| Vendor | Product | Affected Versions | Patch Status |
|---|---|---|---|
| Linux | Linux |
| Subsystems | General OT |
| Sectors | Multiple |
In the Linux kernel, the following vulnerability has been resolved:
afs: Fix incorrect free in candidate cleanup in afs_lookup_server()
Fix afs_lookup_server() to not free an existing server's endpoint state
when cleaning up a candidate server. The candidate record doesn't have an
endpoint state yet at this point, so the free for that can just be removed. (NVD)
Monitor Linux's web page for any future patch releases.
| Source | Reference |
|---|---|
| NVD | https://nvd.nist.gov/vuln/detail/CVE-2026-97584 |
| CVE | https://www.cve.org/CVERecord?id=CVE-2026-97584 |