{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.19.14-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  cachefiles: fix incorrect dentry refcount in cachefiles_cull()  The patch mentioned below changed cachefiles_bury_object() to expect 2 references to the 'rep' dentry.  Three of the callers were changed to use start_removing_dentry() which takes an extra reference so in those cases the call gets the expected references.  However there is another call to cachefiles_bury_object() in cachefiles_cull() which did not need to be changed to use start_removing_dentry() and so was not properly considered. It still passed the dentry with just one reference so the net result is that a reference is lost.  To meet the expectations of cachefiles_bury_object(), cachefiles_cull() must take an extra reference before the call.  It will be dropped by cachefiles_bury_object().",
  "id": "DEBIAN-CVE-2026-43106",
  "modified": "2026-09-14T16:47:46.193874953Z",
  "published": "2026-05-06T10:16:24.213Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-43106"
    }
  ],
  "severity": [
    {
      "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "type": "CVSS_V3"
    }
  ],
  "upstream": [
    "CVE-2026-43106"
  ]
}