{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.12.100-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "7.1.4-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux-6.12"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.12.100-1~deb12u1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  mm: swap_cgroup: fix NULL deref in lookup_swap_cgroup_id on swapless host  lookup_swap_cgroup_id() passes swap_cgroup_ctrl[type].map to __swap_cgroup_id_lookup() without checking that the type was ever registered via swap_cgroup_swapon().  On a swapless host every ctrl-\u003emap is NULL, so __swap_cgroup_id_lookup() dereferences NULL + a scaled swp_offset().  Since commit bea67dcc5eea (\"mm: attempt to batch free swap entries for zap_pte_range()\"), zap_pte_range() -\u003e swap_pte_batch() calls lookup_swap_cgroup_id() on any non-present, non-none PTE that decodes as a real swap entry, without first validating it against swap_info[].  A single PTE corrupted into a type-0 swap entry takes the host down at process exit.  We hit this in production on a swapless 6.12.58 host: ~1s of \"get_swap_device: Bad swap file entry 3f800204222bb\" (do_swap_page() being correctly defensive about the same entry) followed by    BUG: unable to handle page fault for address: 000003f800204220   RIP: 0010:lookup_swap_cgroup_id+0x2b/0x60   Call Trace:    swap_pte_batch+0xbf/0x230    zap_pte_range+0x4c8/0x780    unmap_page_range+0x190/0x3e0    exit_mmap+0xd9/0x3c0    do_exit+0x20c/0x4b0  syzbot has reported the identical stack.  The source of the PTE corruption is a separate bug; this change makes the teardown path as robust as the fault path already is.  Every other caller of lookup_swap_cgroup_id() is downstream of a get_swap_device() that has already validated the entry, so the new branch is cold.",
  "id": "DEBIAN-CVE-2026-64416",
  "modified": "2026-09-14T16:47:45.666795265Z",
  "published": "2026-07-25T10:17:25.453Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-64416"
    }
  ],
  "severity": [
    {
      "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
      "type": "CVSS_V3"
    }
  ],
  "upstream": [
    "CVE-2026-64416"
  ]
}