{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  ufs: validate cylinder group metadata before caching it  ufs_read_cylinder() copies the cylinder group index and the rotor positions straight from the on-disk group and caches them without any check:  \tucpi-\u003ec_cgx    = fs32_to_cpu(sb, ucg-\u003ecg_cgx); \tucpi-\u003ec_rotor  = fs32_to_cpu(sb, ucg-\u003ecg_rotor); \tucpi-\u003ec_frotor = fs32_to_cpu(sb, ucg-\u003ecg_frotor); \tucpi-\u003ec_irotor = fs32_to_cpu(sb, ucg-\u003ecg_irotor);  They are then used as indices during allocation and free:    - c_cgx indexes the cylinder summary array as     UFS_SB(sb)-\u003efs_cs(ucpi-\u003ec_cgx), so a value past s_ncg writes a 32     bit count outside the s_csp allocation.    - c_frotor becomes a bitmap scan start, start = c_frotor \u003e\u003e 3, and     then length = ((s_fpg + 7) \u003e\u003e 3) - start. A start beyond the block     bitmap wraps the unsigned length to a huge value, so ubh_scanc()     walks far past the cylinder group buffers. c_irotor drives the     inode bitmap the same way.  A crafted image can set any of these freely, turning an ordinary allocation into an out of bounds access.  Reject a cylinder group whose recorded index does not match the group being read, or whose rotors fall outside the group, before the metadata is cached. Valid filesystems keep cg_cgx equal to the group number and the rotors within the group, so only malformed images are rejected.",
  "id": "DEBIAN-CVE-2026-97926",
  "modified": "2026-09-26T04:47:37.839219633Z",
  "published": "2026-09-25T11:17:19.833Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-97926"
    }
  ],
  "severity": [
    {
      "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
      "type": "CVSS_V3"
    }
  ],
  "upstream": [
    "CVE-2026-97926"
  ]
}