{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "7.0.12-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  zram: fix use-after-free in zram_writeback_endio  A crash was observed in zram_writeback_endio due to a NULL pointer dereference in wake_up.  The root cause is a race condition between the bio completion handler (zram_writeback_endio) and the writeback task.  In zram_writeback_endio, wake_up() is called on \u0026wb_ctl-\u003edone_wait after releasing wb_ctl-\u003edone_lock.  This creates a race window where the writeback task can see num_inflight become 0, return, and free wb_ctl before zram_writeback_endio calls wake_up().  CPU 0 (zram_writeback_endio)     CPU 1 (writeback_store) ============================     ============================                                  zram_writeback_slots                                    zram_submit_wb_request                                    zram_submit_wb_request                                    wait_event(wb_ctl-\u003edone_wait) spin_lock(\u0026wb_ctl-\u003edone_lock); list_add(\u0026req-\u003eentry, \u0026wb_ctl-\u003edone_reqs); spin_unlock(\u0026wb_ctl-\u003edone_lock); wake_up(\u0026wb_ctl-\u003edone_wait);                                    zram_complete_done_reqs spin_lock(\u0026wb_ctl-\u003edone_lock); list_add(\u0026req-\u003eentry, \u0026wb_ctl-\u003edone_reqs); spin_unlock(\u0026wb_ctl-\u003edone_lock);                                    while (num_inflight) \u003e 0)                                      spin_lock(\u0026wb_ctl-\u003edone_lock);                                      list_del(\u0026req-\u003eentry);                                      spin_unlock(\u0026wb_ctl-\u003edone_lock);                                      // num_inflight becomes 0                                      atomic_dec(num_inflight);                                   // Leave zram_writeback_slots                                  // Free wb_ctl                                  release_wb_ctl(wb_ctl); // UAF crash! wake_up(\u0026wb_ctl-\u003edone_wait);  This patch fixes this race by using RCU.  By protecting wb_ctl with rcu_read_lock() in zram_writeback_endio and using kfree_rcu() to free it, we ensure that wb_ctl remains valid during the execution of zram_writeback_endio.",
  "id": "DEBIAN-CVE-2026-63951",
  "modified": "2026-10-01T02:47:35.561648861Z",
  "published": "2026-07-19T16:17:13.837Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-63951"
    }
  ],
  "severity": [
    {
      "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "type": "CVSS_V3"
    }
  ],
  "upstream": [
    "CVE-2026-63951"
  ]
}