OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-97584

HIGH · CVSS 7.8 EPSS 0.16%

Source: NVD + CISA KEV + EPSS · Published 2026-09-25 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

A vulnerability in the Linux kernel affects the AFS (Andrew File System) implementation, specifically in the afs_lookup_server() function, where an incorrect memory deallocation could occur during candidate server cleanup. This flaw could potentially lead to memory corruption or instability in systems utilizing AFS, making it critical for organizations relying on Linux servers with AFS to prioritize patching. System administrators and security teams should address this issue to maintain system integrity and prevent potential exploitation.

CVE
CVE-2026-97584
Severity
HIGH
CVSS
7.8
EPSS
0.16%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: afs: Fix incorrect free in candidate cleanup in afs_lookup_server() Fix afs_lookup_server() to not free an existing server's endpoint state when cleaning up a candidate server. The candidate record doesn't have an endpoint state yet at this point, so the free for that can just be removed.