{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.1.180-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.12.100-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "7.1.4-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux-6.12"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.12.100-1~deb12u1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  vfio/mlx5: Fix racy bitfields and tighten struct layout  Bitfield operations are not atomic, they use a read-modify-write pattern, therefore we should be careful not to pack bitfields that can be concurrently updated into the same storage unit.  This split takes a binary approach: flags that are only modified pre/post open/close remain bitfields, flags modified from user action, including actions that reach across to another device (ex. reset) use dedicated storage units.  Note mlx5_vhca_page_tracker.status is relocated to fill the alignment hole this split exposes.  Bitfield justifications:    migrate_cap: written only in mlx5vf_cmd_set_migratable() at probe   chunk_mode: written only in mlx5vf_cmd_set_migratable() at probe   mig_state_cap: written only in mlx5vf_cmd_set_migratable() at probe  Dedicated storage units:    mdev_detach: written in the VF attach/detach event notifier                mlx5fv_vf_event() at runtime   log_active: written in mlx5vf_start_page_tracker()/               mlx5vf_stop_page_tracker() during runtime dirty tracking   deferred_reset: written in mlx5vf_state_mutex_unlock()/                   mlx5vf_pci_aer_reset_done() during runtime reset handling   is_err: set by tracker error handling and dirty-log polling at runtime   object_changed: set by tracker event handling and cleared by dirty-log                   polling at runtime",
  "id": "DEBIAN-CVE-2026-64472",
  "modified": "2026-09-14T16:47:45.712292594Z",
  "published": "2026-07-25T10:17:32.630Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-64472"
    }
  ],
  "upstream": [
    "CVE-2026-64472"
  ]
}