{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.1.177-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.12.95-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "7.1.3-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  NTB: epf: Avoid pci_iounmap() with offset when PEER_SPAD and CONFIG share BAR  When BAR_PEER_SPAD and BAR_CONFIG share one PCI BAR, the module teardown path ends up calling pci_iounmap() on the same iomem with some offset, which is unnecessary and triggers a kernel warning like the following:    Trying to vunmap() nonexistent vm area (0000000069a5ffe8)   WARNING: mm/vmalloc.c:3470 at vunmap+0x58/0x68, CPU#5: modprobe/2937   [...]   Call trace:    vunmap+0x58/0x68 (P)    iounmap+0x34/0x48    pci_iounmap+0x2c/0x40    ntb_epf_pci_remove+0x44/0x80 [ntb_hw_epf]    pci_device_remove+0x48/0xf8    device_remove+0x50/0x88    device_release_driver_internal+0x1c8/0x228    driver_detach+0x50/0xb0    bus_remove_driver+0x74/0x100    driver_unregister+0x34/0x68    pci_unregister_driver+0x34/0xa0    ntb_epf_pci_driver_exit+0x14/0xfe0 [ntb_hw_epf]   [...]  Fix it by unmapping only when PEER_SPAD and CONFIG use difference bars.",
  "id": "DEBIAN-CVE-2026-64254",
  "modified": "2026-09-14T16:47:39.287610045Z",
  "published": "2026-07-24T16:16:55.130Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-64254"
    }
  ],
  "severity": [
    {
      "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
      "type": "CVSS_V3"
    }
  ],
  "upstream": [
    "CVE-2026-64254"
  ]
}