{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.12.85-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.19.14-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  ipvs: fix NULL deref in ip_vs_add_service error path  When ip_vs_bind_scheduler() succeeds in ip_vs_add_service(), the local variable sched is set to NULL.  If ip_vs_start_estimator() subsequently fails, the out_err cleanup calls ip_vs_unbind_scheduler(svc, sched) with sched == NULL.  ip_vs_unbind_scheduler() passes the cur_sched NULL check (because svc-\u003escheduler was set by the successful bind) but then dereferences the NULL sched parameter at sched-\u003edone_service, causing a kernel panic at offset 0x30 from NULL.   Oops: general protection fault, [..] [#1] PREEMPT SMP KASAN NOPTI  KASAN: null-ptr-deref in range [0x0000000000000030-0x0000000000000037]  RIP: 0010:ip_vs_unbind_scheduler (net/netfilter/ipvs/ip_vs_sched.c:69)  Call Trace:   \u003cTASK\u003e   ip_vs_add_service.isra.0 (net/netfilter/ipvs/ip_vs_ctl.c:1500)   do_ip_vs_set_ctl (net/netfilter/ipvs/ip_vs_ctl.c:2809)   nf_setsockopt (net/netfilter/nf_sockopt.c:102)   [..]  Fix by simply not clearing the local sched variable after a successful bind.  ip_vs_unbind_scheduler() already detects whether a scheduler is installed via svc-\u003escheduler, and keeping sched non-NULL ensures the error path passes the correct pointer to both ip_vs_unbind_scheduler() and ip_vs_scheduler_put().  While the bug is older, the problem popups in more recent kernels (6.2), when the new error path is taken after the ip_vs_start_estimator() call.",
  "id": "DEBIAN-CVE-2026-43086",
  "modified": "2026-09-14T16:47:28.297741009Z",
  "published": "2026-05-06T10:16:21.837Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-43086"
    }
  ],
  "severity": [
    {
      "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
      "type": "CVSS_V3"
    }
  ],
  "upstream": [
    "CVE-2026-43086"
  ]
}