{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.1.177-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.12.95-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "7.0.14-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  net: qualcomm: rmnet: fix endpoint use-after-free in rmnet_dellink()  rmnet_dellink() removes the endpoint from the hash table with hlist_del_init_rcu() and then immediately frees it with kfree(). However, RCU readers on the receive path (rmnet_rx_handler -\u003e __rmnet_map_ingress_handler) may still hold a reference to the endpoint and dereference ep-\u003eegress_dev after the memory has been freed. The endpoint is a kmalloc-32 object, and the stale read at offset 8 corresponds to the egress_dev pointer.    BUG: unable to handle page fault for address: ffffffffde942eef   Oops: 0002 [#1] SMP NOPTI   CPU: 1 UID: 0 PID: 137 Comm: poc_write Not tainted 7.0.0+ #4 PREEMPTLAZY   RIP: 0010:rmnet_vnd_rx_fixup (rmnet_vnd.c:27)   Call Trace:    \u003cTASK\u003e    __rmnet_map_ingress_handler (rmnet_handlers.c:48 rmnet_handlers.c:101)    rmnet_rx_handler (rmnet_handlers.c:129 rmnet_handlers.c:235)    __netif_receive_skb_core.constprop.0 (net/core/dev.c:6096)    __netif_receive_skb_one_core (net/core/dev.c:6208)    netif_receive_skb (net/core/dev.c:6467)    tun_get_user (drivers/net/tun.c:1955)    tun_chr_write_iter (drivers/net/tun.c:2003)    vfs_write (fs/read_write.c:688)    ksys_write (fs/read_write.c:740)    \u003c/TASK\u003e  Add an rcu_head field to struct rmnet_endpoint and replace kfree() with kfree_rcu() so the endpoint memory remains valid through the RCU grace period. Also remove the rmnet_vnd_dellink() call and inline only the nr_rmnet_devs decrement, since rmnet_vnd_dellink() would set ep-\u003eegress_dev to NULL during the grace period, creating a data race with lockless readers.",
  "id": "DEBIAN-CVE-2026-64188",
  "modified": "2026-09-14T16:47:39.556843893Z",
  "published": "2026-07-20T17:18:21.853Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-64188"
    }
  ],
  "severity": [
    {
      "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "type": "CVSS_V3"
    }
  ],
  "upstream": [
    "CVE-2026-64188"
  ]
}