{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.1.176-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.12.94-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "7.0.12-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  net: ifb: report ethtool stats over num_tx_queues  ifb_dev_init() allocates dp-\u003etx_private to dev-\u003enum_tx_queues entries via kzalloc_objs(*txp, dev-\u003enum_tx_queues). Both IFB per-queue RX and TX stats live in those entries: ifb_xmit() updates txp-\u003erx_stats using the skb queue mapping, ifb_ri_tasklet() updates txp-\u003etx_stats, and ifb_stats64() aggregates both over dev-\u003enum_tx_queues.  The ethtool stats callbacks instead size and walk the per-queue stats with dev-\u003ereal_num_rx_queues and dev-\u003ereal_num_tx_queues. With an asymmetric device where the RX queue count exceeds the TX queue count, for example:      ip link add name ifb10 numtxqueues 1 numrxqueues 8 type ifb     ethtool -S ifb10  ifb_get_ethtool_stats() indexes past the tx_private allocation and copies adjacent slab data through ETHTOOL_GSTATS.  Use dev-\u003enum_tx_queues consistently for the stats strings, the stats count, and the stats data walks. This reports one RX stats group and one TX stats group for each backing ifb_q_private entry, which is the queue set IFB can actually populate.  Reproduced under UML+KASAN at v7.1-rc2:    BUG: KASAN: slab-out-of-bounds in ifb_fill_stats_data+0x3c/0xae   Read of size 8 at addr 0000000062dbd228 by task ethtool/36   ifb_fill_stats_data+0x3c/0xae   ifb_get_ethtool_stats+0xc0/0x129   __dev_ethtool+0x1ca5/0x363c   dev_ethtool+0x123/0x1b3   dev_ioctl+0x56c/0x744   sock_do_ioctl+0x15f/0x1b2   sock_ioctl+0x4d5/0x50a   sys_ioctl+0xd8b/0xde9  With the patch applied, the same UML+KASAN repro is silent and ethtool -S ifb10 reports only the stats backed by the single allocated tx_private entry.",
  "id": "DEBIAN-CVE-2026-64121",
  "modified": "2026-09-14T16:47:43.199928944Z",
  "published": "2026-07-19T16:17:53.663Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-64121"
    }
  ],
  "severity": [
    {
      "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H",
      "type": "CVSS_V3"
    }
  ],
  "upstream": [
    "CVE-2026-64121"
  ]
}