{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  hinic3: Fix skb linearization mismatch and drop skb when skb_checksum_help() failed  Previously, hinic3_send_one_skb() cached the skb fragment count before calling hinic3_tx_offload(). If hinic3_tx_csum() falls back to skb_checksum_help() for unsupported tunnel packets, the skb may be linearized. Continuing to build the TX descriptor with the stale fragment count leads to a descriptor mismatch, which can trigger out-of-bounds DMA reads or IOMMU faults.  Furthermore, the old code ignored the return value of skb_checksum_help(), transmitting corrupted packets with incomplete checksums upon failure.  Fix this by: 1. Moving the hinic3_tx_offload() call before calculating 'num_sge' to    ensure the correct fragment count is used if the SKB is linearized. 2. Propagating skb_checksum_help() errors and returning    HINIC3_TX_OFFLOAD_INVALID to properly drop the skb.",
  "id": "DEBIAN-CVE-2026-90145",
  "modified": "2026-09-18T04:47:29.627559220Z",
  "published": "2026-09-17T17:17:07.350Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-90145"
    }
  ],
  "upstream": [
    "CVE-2026-90145"
  ]
}