{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  KEYS: trusted: Fix TPM teardown ordering  trusted_tpm_exit() drops the TPM chip reference and frees the digest array before unregistering the trusted key type. key_type_lookup() holds key_types_sem for reading until the key operation finishes, while unregister_key_type() takes it for writing. It therefore provides the synchronization point that must precede backend teardown.  The current order permits this interleaving:    CPU 0                              CPU 1   trusted_tpm_exit()                 key_type_lookup(\"trusted\")     put_device(\u0026chip-\u003edev)             trusted_tpm_seal()     kfree(digests)                       pcrlock()     unregister_key_type()                  tpm_pcr_extend(..., digests)  CPU 1 can consequently dereference the freed digest array. The chip can also be released before callbacks stop using it.  KASAN reported:    BUG: KASAN: slab-use-after-free in tpm_pcr_extend+0x1f0/0x200   Read of size 2 at addr ffff88810872d000 by task poc/89   Call Trace:     tpm_pcr_extend+0x1f0/0x200     pcrlock+0x42/0x70 [trusted]     trusted_tpm_seal+0x1b6/0x570 [trusted]     trusted_instantiate+0x293/0x340 [trusted]     __key_instantiate_and_link+0xb2/0x2b0     __key_create_or_update+0x61e/0xb50     __do_sys_add_key+0x1b8/0x310   Allocated by task 88:     __kmalloc_noprof+0x1a7/0x490     do_one_initcall+0xa1/0x390     do_init_module+0x2df/0x840   Freed by task 90:     kfree+0x131/0x3c0     trusted_tpm_exit+0x59/0xa0 [trusted]     __do_sys_delete_module+0x346/0x510  Move unregister_key_type() before releasing either resource. This stops new lookups and waits for in-flight key operations to finish before the backend state is destroyed.",
  "id": "DEBIAN-CVE-2026-89763",
  "modified": "2026-09-14T08:47:39.397295935Z",
  "published": "2026-09-11T20:20:07.523Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-89763"
    }
  ],
  "severity": [
    {
      "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "type": "CVSS_V3"
    }
  ],
  "upstream": [
    "CVE-2026-89763"
  ]
}