{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "7.1.5-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  tracing/fprobe: Fix NULL pointer dereference in fprobe_fgraph_entry()  fprobe_fgraph_entry() sizes a shadow-stack reservation in one walk of the per-ip fprobe list and fills it in a second walk, both under rcu_read_lock() only. A fprobe registered on an already-live ip can become visible between the two walks, so the fill walk processes an exit_handler the sizing walk did not count and used runs past reserved_words. If the sizing walk counted nothing, fgraph_data is NULL and the first write_fprobe_header() faults:    Oops: general protection fault, probably for non-canonical address ...   KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007]   RIP: 0010:fprobe_fgraph_entry+0xa38/0xf10 kernel/trace/fprobe.c:167   Call Trace:    \u003cTASK\u003e    function_graph_enter_regs+0x44c/0xa10 kernel/trace/fgraph.c:677    ftrace_graph_func+0xc5/0x140 arch/x86/kernel/ftrace.c:671    __kernel_text_address+0x9/0x40 kernel/extable.c:78    arch_stack_walk+0x117/0x170 arch/x86/kernel/stacktrace.c:26    kmem_cache_free+0x188/0x580 mm/slub.c:6378    tcp_data_queue+0x18d/0x6550 net/ipv4/tcp_input.c:5590    [...]    \u003c/TASK\u003e  The list cannot be frozen across the two walks, so skip a node that does not fit the reservation and count it as missed.",
  "id": "DEBIAN-CVE-2026-72385",
  "modified": "2026-09-14T16:47:26.844663600Z",
  "published": "2026-08-15T06:22:12.017Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-72385"
    }
  ],
  "upstream": [
    "CVE-2026-72385"
  ]
}