{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  nvdimm: virtio_pmem: refcount requests for token lifetime  KASAN reports slab-use-after-free in __wake_up_common(): BUG: KASAN: slab-use-after-free in __wake_up_common+0x114/0x160 Read of size 8 at addr ffff88810fdcb710 by task swapper/0/0  CPU: 0 UID: 0 PID: 0 Comm: swapper/0 Not tainted 6.19.0-next-20260220-00006-g1eae5f204ec3 #4 PREEMPT(full) Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS Arch Linux 1.17.0-2-2 04/01/2014 Call Trace:  \u003cIRQ\u003e  dump_stack_lvl+0x6d/0xb0  print_report+0x170/0x4e2  ? __pfx__raw_spin_lock_irqsave+0x10/0x10  ? __virt_addr_valid+0x1dc/0x380  kasan_report+0xbc/0xf0  ? __wake_up_common+0x114/0x160  ? __wake_up_common+0x114/0x160  __wake_up_common+0x114/0x160  ? __pfx__raw_spin_lock_irqsave+0x10/0x10  __wake_up+0x36/0x60  virtio_pmem_host_ack+0x11d/0x3b0  ? sched_balance_domains+0x29f/0xb00  ? __pfx_virtio_pmem_host_ack+0x10/0x10  ? _raw_spin_lock_irqsave+0x98/0x100  ? __pfx__raw_spin_lock_irqsave+0x10/0x10  vring_interrupt+0x1c9/0x5e0  ? __pfx_vp_interrupt+0x10/0x10  vp_vring_interrupt+0x87/0x100  ? __pfx_vp_interrupt+0x10/0x10  __handle_irq_event_percpu+0x17f/0x550  ? __pfx__raw_spin_lock+0x10/0x10  handle_irq_event+0xab/0x1c0  handle_fasteoi_irq+0x276/0xae0  __common_interrupt+0x65/0x130  common_interrupt+0x78/0xa0  \u003c/IRQ\u003e  virtio_pmem_host_ack() wakes a request that has already been freed by the submitter.  This happens when the request token is still reachable via the virtqueue, but virtio_pmem_flush() returns and frees it.  Fix the token lifetime by refcounting struct virtio_pmem_request. virtio_pmem_flush() holds a submitter reference, and the virtqueue holds an extra reference once the request is queued. The completion path drops the virtqueue reference, and the submitter drops its reference before returning.",
  "id": "DEBIAN-CVE-2026-93196",
  "modified": "2026-09-18T04:47:42.148577125Z",
  "published": "2026-09-17T17:18:15.880Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-93196"
    }
  ],
  "upstream": [
    "CVE-2026-93196"
  ]
}