{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.1.176-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.12.94-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "7.0.10-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  net: usb: rtl8150: fix use-after-free in rtl8150_start_xmit()  syzbot reported a KASAN slab-use-after-free read in rtl8150_start_xmit() when accessing skb-\u003elen for tx statistics after usb_submit_urb() has been called:    BUG: KASAN: slab-use-after-free in rtl8150_start_xmit+0x71f/0x760     drivers/net/usb/rtl8150.c:712   Read of size 4 at addr ffff88810eb7a930 by task kworker/0:4/5226  The URB completion handler write_bulk_callback() frees the skb via dev_kfree_skb_irq(dev-\u003etx_skb). The URB may complete on another CPU in softirq context before usb_submit_urb() returns in the submitter, so by the time the submitter reads skb-\u003elen the skb has already been queued to the per-CPU completion_queue and freed by net_tx_action():    CPU A (xmit)                      CPU B (USB completion softirq)   ------------                      ------------------------------   dev-\u003etx_skb = skb;   usb_submit_urb()      --+                           |-------\u003e write_bulk_callback()                           |           dev_kfree_skb_irq(dev-\u003etx_skb)                           |         net_tx_action()                           |           napi_skb_cache_put()   \u003c-- free   netdev-\u003estats.tx_bytes  |     += skb-\u003elen;          \u003c-- UAF read  Fix it by caching skb-\u003elen before submitting the URB and using the cached value when updating the tx_bytes counter.  The pre-existing tx_bytes semantics are preserved: the counter tracks the original frame length (skb-\u003elen), not the ETH_ZLEN/USB-alignment padded \"count\" value that is handed to the device.  Changing that would be a user-visible accounting change and is out of scope for this UAF fix.",
  "id": "DEBIAN-CVE-2026-52982",
  "modified": "2026-09-14T16:47:33.585604387Z",
  "published": "2026-06-24T17:17:08.887Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-52982"
    }
  ],
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "type": "CVSS_V3"
    }
  ],
  "upstream": [
    "CVE-2026-52982"
  ]
}