{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  reboot: fix cad_pid use-after-free race  cad_pid is a single kernel-wide struct pid pointer. proc_do_cad_pid() reads it and passes it to pid_vnr() without protecting the lifetime of the referenced struct pid. A concurrent writer can replace cad_pid and drop the final reference to the old struct pid after the reader has loaded the pointer but before pid_vnr() has finished dereferencing it, causing a use-after-free.  kill_cad_pid() has the same lifetime race when it passes cad_pid to kill_pid().  At the time this issue was reported, an unprivileged user could reach the sysctl through user and PID namespaces because cad_pid was registered in pid_table[]. Moving cad_pid back to the global reboot sysctl table corrected that namespace and permission mismatch, but did not fix the underlying lifetime race.  Fix this by treating cad_pid as an RCU-protected pointer at both read sites and by waiting for a grace period before dropping the old reference on the write side.  call_rcu(\u0026old_pid-\u003ercu, ...) cannot be used here because free_pid() also queues pid-\u003ercu; queueing the same rcu_head twice can corrupt the RCU callback list.  Original KASAN crash stack:   kernel/pid.c:545 pid_nr_ns()        # reads freed pid-\u003elevel   kernel/pid.c:556 pid_vnr()          # calls pid_nr_ns()   kernel/pid.c:775 proc_do_cad_pid()  # calls pid_vnr(cad_pid)",
  "id": "DEBIAN-CVE-2026-97938",
  "modified": "2026-09-26T04:47:37.315731754Z",
  "published": "2026-09-25T11:17:21.193Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-97938"
    }
  ],
  "upstream": [
    "CVE-2026-97938"
  ]
}