{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  netfs: break unbuffered write when netfs_alloc_subrequest() fails  syzbot reported a null-ptr-deref below [1] following a fault injection in netfs_alloc_subrequest(). [0]  When netfs_alloc_subrequest() fails, subreq is NULL. Later, netfs_prepare_write() tries to initialize members of subreq(e.g., source), the issue in [1] is triggered.  Let's handle the error of netfs_prepare_write() properly.  [0] FAULT_INJECTION: forcing a failure. name failslab, interval 1, probability 0, space 0, times 0 Call Trace:  netfs_alloc_subrequest+0x116/0x3f0  netfs_prepare_write+0x76/0x7b0  netfs_unbuffered_write+0x75c/0x2020  netfs_unbuffered_write_iter_locked+0x7d6/0xa80  netfs_unbuffered_write_iter+0x442/0x720  v9fs_file_write_iter+0xbf/0x100  vfs_write+0x6ac/0x1050  [1] KASAN: null-ptr-deref in range [0x00000000000000a8-0x00000000000000af] RIP: 0010:netfs_prepare_write+0xbc/0x7b0 fs/netfs/write_issue.c:173 Call Trace:  netfs_unbuffered_write+0x75c/0x2020 fs/netfs/direct_write.c:111  netfs_unbuffered_write_iter_locked+0x7d6/0xa80 fs/netfs/direct_write.c:290  netfs_unbuffered_write_iter+0x442/0x720 fs/netfs/direct_write.c:382  v9fs_file_write_iter+0xbf/0x100 fs/9p/vfs_file.c:409  new_sync_write fs/read_write.c:595 [inline]",
  "id": "DEBIAN-CVE-2026-98119",
  "modified": "2026-09-26T04:47:29.479318009Z",
  "published": "2026-09-25T11:17:43.140Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-98119"
    }
  ],
  "upstream": [
    "CVE-2026-98119"
  ]
}