{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  exit: hold a reference to thread_pid across proc_flush_pid  Commit 0a36bad01731 (\"release_task: kill the no longer needed get/put_pid(thread_pid)\") removed the reference around proc_flush_pid(). It assumed that free_pids(post.pids) at the end of release_task() would keep thread_pid alive until then.  That assumption is wrong.  __change_pid() only records a detached PID in post.pids when pid_has_task() is false for every PIDTYPE.  If another task still uses the exiting task's PID as its process group or session ID, __unhash_process() removes the exiting task's PIDTYPE_PID link but leaves the PID out of post.pids.  release_task() therefore holds no reference to it after dropping tasklist_lock.  The other task can then remove the remaining PIDTYPE links.  Its free_pids() call schedules delayed_put_pid(), and the RCU callback can free the PID before the first release_task() reaches proc_flush_pid().  An unprivileged reproducer races wait4(-1) against setsid() to trigger this ordering.  Three of three fresh v7.2 KASAN boots reported:      BUG: KASAN: slab-use-after-free in     proc_invalidate_siblings_dcache+0x3e2/0x3f0     Read of size 8 by task h7_pid_reaper/1921      Call Trace:      proc_invalidate_siblings_dcache      release_task      wait_consider_task      __do_wait      do_wait      kernel_wait4      Freed by task 0:      kmem_cache_free      put_pid      delayed_put_pid      rcu_core      Last potentially related work creation:      __call_rcu_common      free_pids      ksys_setsid  KASAN identified a 144-byte object from the pid cache and located the bad read 80 bytes into the freed object, matching pid-\u003einodes.  With an explicit reference, three of three fresh boots completed without a KASAN report.  The concurrent RCU callback dropped its reference while proc_flush_pid() was protected, and the balancing put_pid() performed the final free afterward.  Take a reference before __unhash_process() clears p-\u003ethread_pid and release it after proc_flush_pid() completes.  A tested source reproducer is available privately on request.  No controlled read or write, information leak, or privilege escalation is claimed.  The mainline patch applies directly to v6.19.y and newer; v6.16.y through v6.18.y need a context-adjusted backport.",
  "id": "DEBIAN-CVE-2026-97903",
  "modified": "2026-09-26T04:47:37.472643149Z",
  "published": "2026-09-25T11:17:17.150Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-97903"
    }
  ],
  "severity": [
    {
      "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "type": "CVSS_V3"
    }
  ],
  "upstream": [
    "CVE-2026-97903"
  ]
}