{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.12.85-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.19.6-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  md-cluster: fix NULL pointer dereference in process_metadata_update  The function process_metadata_update() blindly dereferences the 'thread' pointer (acquired via rcu_dereference_protected) within the wait_event() macro.  While the code comment states \"daemon thread must exist\", there is a valid race condition window during the MD array startup sequence (md_run):  1. bitmap_load() is called, which invokes md_cluster_ops-\u003ejoin(). 2. join() starts the \"cluster_recv\" thread (recv_daemon). 3. At this point, recv_daemon is active and processing messages. 4. However, mddev-\u003ethread (the main MD thread) is not initialized until    later in md_run().  If a METADATA_UPDATED message is received from a remote node during this specific window, process_metadata_update() will be called while mddev-\u003ethread is still NULL, leading to a kernel panic.  To fix this, we must validate the 'thread' pointer. If it is NULL, we release the held lock (no_new_dev_lockres) and return early, safely ignoring the update request as the array is not yet fully ready to process it.",
  "id": "DEBIAN-CVE-2026-43271",
  "modified": "2026-09-14T16:47:37.633433167Z",
  "published": "2026-05-06T12:16:48.313Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-43271"
    }
  ],
  "severity": [
    {
      "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
      "type": "CVSS_V3"
    }
  ],
  "upstream": [
    "CVE-2026-43271"
  ]
}