{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.12.94-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "7.0.13-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  net/mlx5e: xsk: Fix DMA and xdp_frame leak on XDP_TX xmit failure  In the XSK branch of mlx5e_xmit_xdp_buff(), when sq-\u003exmit_xdp_frame() returns false (e.g. XDPSQ is full), the function returns without unmapping the DMA address or freeing the xdp_frame allocated by xdp_convert_zc_to_xdp_frame(). The xdpi_fifo push only happens on success, so the completion path cannot recover these entries.  With CONFIG_DMA_API_DEBUG=y, the leak surfaces on driver unbind:    DMA-API: pci 0000:08:00.0: device driver has pending DMA   allocations while released from device [count=1116]   One of leaked entries details: [device address=0x000000010ffd7028]   [size=1534 bytes] [mapped with DMA_TO_DEVICE] [mapped as phy]   WARNING: kernel/dma/debug.c:881 at dma_debug_device_change+0x127/0x180   ...   DMA-API: Mapped at:    debug_dma_map_phys+0x4b/0xd0    dma_map_phys+0xfd/0x2d0    mlx5e_xdp_handle+0x5ae/0xac0 [mlx5_core]    mlx5e_xsk_skb_from_cqe_mpwrq_linear+0xc4/0x170 [mlx5_core]    mlx5e_handle_rx_cqe_mpwrq+0xc1/0x290 [mlx5_core]  Add the missing unmap + xdp_return_frame, matching the cleanup already done in mlx5e_xdp_xmit(). has_frags is rejected earlier in this branch, so no per-frag unmap is needed.",
  "id": "DEBIAN-CVE-2026-53229",
  "modified": "2026-09-14T16:47:32.804886219Z",
  "published": "2026-06-25T09:16:40.793Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-53229"
    }
  ],
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "type": "CVSS_V3"
    }
  ],
  "upstream": [
    "CVE-2026-53229"
  ]
}