{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "7.0.10-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  fuse: fix uninit-value in fuse_dentry_revalidate()  fuse_dentry_revalidate() may be called with a dentry that didn't had -\u003ed_time initialised.  The issue was found with KMSAN, where lookup_open() calls __d_alloc(), followed by d_revalidate(), as shown below:  ===================================================== BUG: KMSAN: uninit-value in fuse_dentry_revalidate+0x150/0x13d0 fs/fuse/dir.c:394  fuse_dentry_revalidate+0x150/0x13d0 fs/fuse/dir.c:394  d_revalidate fs/namei.c:1030 [inline]  lookup_open fs/namei.c:4405 [inline]  open_last_lookups fs/namei.c:4583 [inline]  path_openat+0x1614/0x64c0 fs/namei.c:4827  do_file_open+0x2aa/0x680 fs/namei.c:4859 [...]  Uninit was created at:  slab_post_alloc_hook mm/slub.c:4466 [inline]  slab_alloc_node mm/slub.c:4788 [inline]  kmem_cache_alloc_lru_noprof+0x382/0x1280 mm/slub.c:4807  __d_alloc+0x55/0xa00 fs/dcache.c:1740  d_alloc_parallel+0x99/0x2740 fs/dcache.c:2604  lookup_open fs/namei.c:4398 [inline]  open_last_lookups fs/namei.c:4583 [inline]  path_openat+0x135f/0x64c0 fs/namei.c:4827  do_file_open+0x2aa/0x680 fs/namei.c:4859 [...] =====================================================",
  "id": "DEBIAN-CVE-2026-53311",
  "modified": "2026-09-14T16:47:44.409859887Z",
  "published": "2026-06-26T20:17:24.423Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-53311"
    }
  ],
  "severity": [
    {
      "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
      "type": "CVSS_V3"
    }
  ],
  "upstream": [
    "CVE-2026-53311"
  ]
}