{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "7.1.5-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  eth: fbnic: don't cache shinfo across skb realloc  fbnic_tx_lso() calls skb_cow_head() which may reallocate the skb including the shared info. We can't use the pointer calculated before the call.      BUG: KASAN: slab-use-after-free in fbnic_tx_lso.isra.0+0x668/0x8e0     Read of size 4 at addr ff110000262edd98 by task swapper/5/0     Call Trace:      fbnic_tx_lso.isra.0+0x668/0x8e0      fbnic_xmit_frame+0x622/0xba0      dev_hard_start_xmit+0xf4/0x620      Allocated by task 8653:      __alloc_skb+0x11e/0x5f0      alloc_skb_with_frags+0xcc/0x6c0      sock_alloc_send_pskb+0x327/0x3f0      __ip_append_data+0x188b/0x47a0      ip_make_skb+0x24a/0x300      udp_sendmsg+0x14d2/0x21e0      Freed by task 0:      kfree+0x123/0x5a0      pskb_expand_head+0x36c/0xfa0      fbnic_tx_lso.isra.0+0x500/0x8e0      fbnic_xmit_frame+0x622/0xba0      dev_hard_start_xmit+0xf4/0x620      sch_direct_xmit+0x25b/0x1100      The buggy address belongs to the object at ff110000262edc40      which belongs to the cache skbuff_small_head of size 640     The buggy address is located 344 bytes inside of      freed 640-byte region [ff110000262edc40, ff110000262ede",
  "id": "DEBIAN-CVE-2026-72393",
  "modified": "2026-09-14T16:47:30.872113548Z",
  "published": "2026-08-15T06:22:12.847Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-72393"
    }
  ],
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "type": "CVSS_V3"
    }
  ],
  "upstream": [
    "CVE-2026-72393"
  ]
}