{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.19.6-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  gfs2: fix memory leaks in gfs2_fill_super error path  Fix two memory leaks in the gfs2_fill_super() error handling path when transitioning a filesystem to read-write mode fails.  First leak: kthread objects (thread_struct, task_struct, etc.) When gfs2_freeze_lock_shared() fails after init_threads() succeeds, the created kernel threads (logd and quotad) are never destroyed. This occurs because the fail_per_node label doesn't call gfs2_destroy_threads().  Second leak: quota bitmap buffer (8192 bytes) When gfs2_make_fs_rw() fails after gfs2_quota_init() succeeds but before other operations complete, the allocated quota bitmap is never freed.  The fix moves thread cleanup to the fail_per_node label to handle all error paths uniformly. gfs2_destroy_threads() is safe to call unconditionally as it checks for NULL pointers. Quota cleanup is added in gfs2_make_fs_rw() to properly handle the withdrawal case where quota initialization succeeds but the filesystem is then withdrawn.  Thread leak backtrace (gfs2_freeze_lock_shared failure):   unreferenced object 0xffff88801d7bca80 (size 4480):     copy_process+0x3a1/0x4670 kernel/fork.c:2422     kernel_clone+0xf3/0x6e0 kernel/fork.c:2779     kthread_create_on_node+0x100/0x150 kernel/kthread.c:478     init_threads+0xab/0x350 fs/gfs2/ops_fstype.c:611     gfs2_fill_super+0xe5c/0x1240 fs/gfs2/ops_fstype.c:1265  Quota leak backtrace (gfs2_make_fs_rw failure):   unreferenced object 0xffff88812de7c000 (size 8192):     gfs2_quota_init+0xe5/0x820 fs/gfs2/quota.c:1409     gfs2_make_fs_rw+0x7a/0xe0 fs/gfs2/super.c:149     gfs2_fill_super+0xfbb/0x1240 fs/gfs2/ops_fstype.c:1275",
  "id": "DEBIAN-CVE-2026-45961",
  "modified": "2026-09-14T16:47:39.921593770Z",
  "published": "2026-05-27T14:17:12.783Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-45961"
    }
  ],
  "severity": [
    {
      "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
      "type": "CVSS_V3"
    }
  ],
  "upstream": [
    "CVE-2026-45961"
  ]
}