{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  qede: Fix NULL pointer dereference in TPA fragment processing  Under memory pressure, the qede driver encounters NULL pointer dereferences when processing TPA continuation fragments.  Commit 8a8633978b84 (\"qede: Add build_skb() support.\") accidentally dropped the assignment of tpa_info-\u003ebuffer.data in qede_tpa_start().  When memory pressure causes an SKB allocation failure in qede_tpa_start(), the driver sets tpa_start_fail = true and attempts to recycle the physical page later in qede_tpa_end() via qede_reuse_page(). However, because buffer.data was left uninitialized (NULL), qede_reuse_page() pushes a \"ghost\" BD (valid DMA mapping but NULL data pointer) back into the active Rx ring.  The next time the hardware uses this ring slot, it passes a NULL page to qede_fill_frag_skb(), causing a kernel panic.  Example crash from production system:  BUG: unable to handle kernel NULL pointer dereference at 0x8  RIP: qede_fill_frag_skb+0x96/0x430 [qede]  Call Trace:    qede_rx_int+0xb06/0x1de0    qede_poll+0x2f4/0x6c0    __napi_poll+0x2d/0x130  Fix the root cause by restoring the tpa_info-\u003ebuffer.data assignment in qede_tpa_start(), ensuring valid pages are correctly tracked and recycled. Additionally, update the stale comment for struct qede_agg_info::buffer to reflect its current usage.",
  "id": "DEBIAN-CVE-2026-89511",
  "modified": "2026-09-15T08:47:49.252955084Z",
  "published": "2026-09-11T20:19:33.513Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-89511"
    }
  ],
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "type": "CVSS_V3"
    }
  ],
  "upstream": [
    "CVE-2026-89511"
  ]
}