A vulnerability categorized as problematic has been discovered in Linux Kernel up to 6.12.96/6.18.39/7.1.4/7.2-rc1. Affected is the function idr_alloc_cyclic of the component AFS. The manipulation of the argument cells_outstanding results in return of wrong status code.

This vulnerability is reported as CVE-2026-72376. The attack can be launched remotely. No exploit exists.

It is advisable to upgrade the affected component.