{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  smb/server: fix null-ptr-deref in ksmbd_ipc_tree_connect_request()  See the procedure below:    ksmbd_tree_conn_connect     ksmbd_share_config_get       share-\u003ename = kstrdup() // fail       if (!test_share_config_flag(share, KSMBD_SHARE_FLAG_PIPE)) // false       // do not check `share-\u003ename`     ksmbd_ipc_tree_connect_request       strlen(share-\u003ename) // null-ptr-deref",
  "id": "DEBIAN-CVE-2026-90166",
  "modified": "2026-09-18T04:47:34.474550453Z",
  "published": "2026-09-17T17:17:09.980Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-90166"
    }
  ],
  "upstream": [
    "CVE-2026-90166"
  ]
}