{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.12.96-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  mm/shrinker: do not hold RCU lock in shrinker_debugfs_count_show()  Reading the debugfs \"count\" file of a memcg-aware shrinker can sleep inside an RCU read-side critical section:    BUG: sleeping function called from invalid context at kernel/cgroup/rstat.c:421   RCU nest depth: 1, expected: 0    css_rstat_flush    mem_cgroup_flush_stats    zswap_shrinker_count    shrinker_debugfs_count_show  shrinker_debugfs_count_show() invokes the -\u003ecount_objects() callback under rcu_read_lock().  The zswap callback flushes memcg stats via css_rstat_flush(), which may sleep, so it must not run under RCU.  The RCU lock is not needed here.  mem_cgroup_iter() takes RCU internally and returns a memcg holding a css reference (dropped on the next iteration or by mem_cgroup_iter_break()), so the memcg stays alive without it.  The shrinker is kept alive by the open debugfs file: shrinker_free() removes the debugfs entries via debugfs_remove_recursive(), which waits for in-flight readers to drain, before call_rcu(..., shrinker_free_rcu_cb).  The sibling \"scan\" handler already invokes the sleeping -\u003escan_objects() callback with no RCU section.  Drop the rcu_read_lock()/rcu_read_unlock().",
  "id": "DEBIAN-CVE-2026-64419",
  "modified": "2026-07-26T08:48:17.206892654Z",
  "published": "2026-07-25T10:17:25.847Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-64419"
    }
  ],
  "upstream": [
    "CVE-2026-64419"
  ]
}