{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.19.6-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  ima: Fix stack-out-of-bounds in is_bprm_creds_for_exec()  KASAN reported a stack-out-of-bounds access in ima_appraise_measurement from is_bprm_creds_for_exec:  BUG: KASAN: stack-out-of-bounds in ima_appraise_measurement+0x12dc/0x16a0  Read of size 1 at addr ffffc9000160f940 by task sudo/550 The buggy address belongs to stack of task sudo/550 and is located at offset 24 in frame:   ima_appraise_measurement+0x0/0x16a0 This frame has 2 objects:   [48, 56) 'file'   [80, 148) 'hash'  This is caused by using container_of on the *file pointer. This offset calculation is what triggers the stack-out-of-bounds error.  In order to fix this, pass in a bprm_is_check boolean which can be set depending on how process_measurement is called. If the caller has a linux_binprm pointer and the function is BPRM_CHECK we can determine is_check and set it then. Otherwise set it to false.",
  "id": "DEBIAN-CVE-2025-71306",
  "modified": "2026-09-01T19:48:45.145575645Z",
  "published": "2026-05-27T14:16:43.167Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2025-71306"
    }
  ],
  "severity": [
    {
      "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H",
      "type": "CVSS_V3"
    }
  ],
  "upstream": [
    "CVE-2025-71306"
  ]
}