{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.12.111-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  perf/core: Allow list_del during perf_event_overflow()  A PMU might use perf_sched_cb_inc() and perf_sched_cb_dec() interface to get the PMU call back function pmu::sched_task invoked at schedule in and schedule out. This is achieved by walking along the list anchored by sched_cb_list.  The following scenario might lead to a list corruption.     perf_pmu_sched_task()       for_each_list_entry(..., \u0026sched_cb_list)       +--\u003e __perf_pmu_sched_task()            +--\u003e event-\u003epmu-\u003esched_task())                 +--\u003e PMU_push_sample()                      +--\u003e perf_event_overflow()                           +--\u003e __perf_event_overflow()                                +--\u003e pmu-\u003estop()                                     +--\u003e perf_sched_cb_dec()                                          remove entry from sched_cb_list                                          while list node in use.  This happens when ioctl(fd, PERF_EVENT_IOC_REFRESH, xxx) has been invoked and perf_event::event_limit hits zero.  Prevent the list corruption and convert for_each_list_entry() to for_each_list_entry_safe().",
  "id": "DEBIAN-CVE-2026-97961",
  "modified": "2026-09-29T10:47:33.125994143Z",
  "published": "2026-09-25T11:17:23.860Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-97961"
    }
  ],
  "upstream": [
    "CVE-2026-97961"
  ]
}