{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "7.2.6-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  ipv6: use RCU iterator to dump route exceptions  rt6_nh_dump_exceptions() uses hlist_for_each_entry() to iterate over RCU-protected exception lists. The caller holds rcu_read_lock(), but does not hold rt6_exception_lock, so rt6_insert_exception() can concurrently add an entry with hlist_add_head_rcu().  KCSAN reports this race (irrelevant details omitted):    ==================================================================   BUG: KCSAN: data-race in rt6_insert_exception / rt6_nh_dump_exceptions    write (marked) to 0xffff8a7c44c59620 of 8 bytes by interrupt on cpu 5:     rt6_insert_exception+0x3bb/0x760     __ip6_rt_update_pmtu+0x4fe/0x750     ip6_sk_update_pmtu+0x19a/0x3b0     udpv6_err+0x3ff/0x800     icmpv6_notify+0x1e1/0x440     icmpv6_rcv+0x8c0/0xab0     ip6_protocol_deliver_rcu+0x616/0x840     ip6_input_finish+0xb9/0x160     ...     entry_SYSCALL_64_after_hwframe+0x77/0x7f    read to 0xffff8a7c44c59620 of 8 bytes by task 549 on cpu 14:     rt6_nh_dump_exceptions+0xb3/0x260     rt6_dump_route+0x53e/0x5f0     fib6_dump_node+0x6d/0xf0     fib6_walk_continue+0x290/0x2d0     fib6_dump_table+0x28d/0x360     inet6_dump_fib+0x37d/0x620     rtnl_dumpit+0x7b/0xd0     netlink_dump+0x3ae/0x7e0     ...     entry_SYSCALL_64_after_hwframe+0x77/0x7f    4 locks held by dumper/549:     ...     #1: (rcu_read_lock){....}-{1:3}, at: inet6_dump_fib+0x88/0x620     #2: (\u0026tb-\u003etb6_lock){+.-.}-{3:3}, at: fib6_dump_table+0x1e9/0x360     #3: (rcu_read_lock){....}-{1:3}, at: rt6_dump_route+0x483/0x5f0    value changed: 0xffff8a7c44e05700 -\u003e 0xffff8a7c45d60100    Reported by Kernel Concurrency Sanitizer on:   CPU: 14 UID: 0 PID: 549 Comm: dumper Not tainted   7.2.0-rc7-virtme #38 PREEMPT(lazy)   ...  Use hlist_for_each_entry_rcu() to safely iterate over the exception list.",
  "id": "DEBIAN-CVE-2026-93226",
  "modified": "2026-09-25T04:47:23.680803940Z",
  "published": "2026-09-24T16:17:17.973Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-93226"
    }
  ],
  "upstream": [
    "CVE-2026-93226"
  ]
}