{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "7.1.5-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  gpib: fix double decrement of descriptor_busy in command_ioctl()  commit d1857f8296dc (\"gpib: fix use-after-free in IO ioctl handlers\") introduced a descriptor_busy reference counter to pin struct gpib_descriptor across IO ioctl operations.  In command_ioctl(), the error path inside the loop decrements descriptor_busy and breaks, but execution then falls through to the unconditional decrement after the loop, underflowing the counter to -1.  This re-enables the use-after-free that the original fix was meant to prevent: a concurrent close_dev_ioctl() sees descriptor_busy == 0 on an actively-used descriptor and frees it.  Remove the early decrement from the error path.  The post-loop decrement already handles all exit paths, matching the correct pattern used in read_ioctl() and write_ioctl().",
  "id": "DEBIAN-CVE-2026-72482",
  "modified": "2026-09-14T16:47:34.437892465Z",
  "published": "2026-08-15T06:22:22.430Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-72482"
    }
  ],
  "severity": [
    {
      "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "type": "CVSS_V3"
    }
  ],
  "upstream": [
    "CVE-2026-72482"
  ]
}