{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.1.187-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.12.105-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "7.1.10-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux-6.12"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.12.107-1~deb12u1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  ceph: avoid fs reclaim while using current-\u003ejournal_info  handle_reply() stores a `ceph_mds_request` pointer in `current-\u003ejournal_info` while filling the inode and dentry cache from an MDS reply.  An allocation in this section can enter direct reclaim and prune dentries from another filesystem.  If this dirties an ext4 inode, ext4 starts a JBD2 transaction.  JBD2 interprets the Ceph request in `current-\u003ejournal_info` as a journal handle and dereferences the request's `r_tid` as `h_transaction`, causing a kernel crash, e.g.:   Unable to handle kernel paging request at virtual address 00000000077b4818  [...]  Internal error: Oops: 0000000096000004 [#1]  SMP  Modules linked in:  CPU: 6 UID: 0 PID: 2699135 Comm: kworker/6:3 Tainted: G        W           6.18.38-i3 #1113 NONE  [...]  Workqueue: ceph-msgr ceph_con_workfn  pstate: 80400009 (Nzcv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)  pc : jbd2__journal_start+0x2c/0x208  lr : __ext4_journal_start_sb+0x100/0x178  [...]  Call trace:   jbd2__journal_start+0x2c/0x208 (P)   __ext4_journal_start_sb+0x100/0x178   ext4_dirty_inode+0x3c/0x90   __mark_inode_dirty+0x58/0x400   iput.part.0+0x2b0/0x370   iput+0x18/0x30   dentry_unlink_inode+0xc0/0x158   __dentry_kill+0x80/0x250   shrink_dentry_list+0x90/0x130   prune_dcache_sb+0x60/0x98   super_cache_scan+0xe8/0x190   do_shrink_slab+0x174/0x388   shrink_slab+0xd8/0x4c0   shrink_node+0x31c/0x908   do_try_to_free_pages+0xd0/0x508   try_to_free_pages+0x11c/0x238   __alloc_frozen_pages_noprof+0x4d0/0xdd0   __folio_alloc_noprof+0x18/0x70   __filemap_get_folio+0x248/0x440   ceph_readdir_prepopulate+0x570/0x9e8   mds_dispatch+0x1424/0x1ba0   ceph_con_process_message+0x74/0xa0   ceph_con_v1_try_read+0x3a0/0x1510   ceph_con_workfn+0x260/0x460  Enter a scoped NOFS allocation context and leave it after clearing `journal_info`.  This prevents filesystem reclaim from recursing into another filesystem while the field contains Ceph-private data.",
  "id": "DEBIAN-CVE-2026-80528",
  "modified": "2026-09-19T21:47:24.082639607Z",
  "published": "2026-08-26T15:17:06.667Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-80528"
    }
  ],
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "type": "CVSS_V3"
    }
  ],
  "upstream": [
    "CVE-2026-80528"
  ]
}