{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.1.176-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.12.94-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "7.0.12-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  net: mana: Add NULL guards in teardown path to prevent panic on attach failure  When queue allocation fails partway through, the error cleanup frees and NULLs apc-\u003etx_qp and apc-\u003erxqs. Multiple teardown paths such as mana_remove(), mana_change_mtu() recovery, and internal error handling in mana_alloc_queues() can subsequently call into functions that dereference these pointers without NULL checks:  - mana_chn_setxdp() dereferences apc-\u003erxqs[0], causing a NULL pointer   dereference panic (CR2: 0000000000000000 at mana_chn_setxdp+0x26). - mana_destroy_vport() iterates apc-\u003erxqs without a NULL check. - mana_fence_rqs() iterates apc-\u003erxqs without a NULL check. - mana_dealloc_queues() iterates apc-\u003etx_qp without a NULL check.  Add NULL guards for apc-\u003erxqs in mana_fence_rqs(), mana_destroy_vport(), and before the mana_chn_setxdp() call. Add a NULL guard for apc-\u003etx_qp in mana_dealloc_queues() to skip TX queue draining when TX queues were never allocated or already freed.",
  "id": "DEBIAN-CVE-2026-63973",
  "modified": "2026-10-01T00:47:51.111800859Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-63973"
    }
  ],
  "upstream": [
    "CVE-2026-63973"
  ]
}