{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "7.2.8-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  drm/amdgpu: check ras and obj before dereference  nbio_v7_9_handle_ras_controller_intr_no_bifring() dereferences ras and obj without checking either for NULL. Both amdgpu_ras_get_context() and amdgpu_ras_find_obj() can return NULL, e.g. during the window between adev-\u003enbio.ras being set (early in amdgpu_ras_init(), by design, to enable the fatal-error interrupt as soon as possible) and the PCIE_BIF ras object actually being created in RAS late_init. Any interrupt in that window crashes in hard-IRQ context.  This is analogous to commit d190b459b2a4 (\"drm/amdgpu: the warning dereferencing obj for nbio_v7_4\"), which fixed the same issue in the nbio_v7_4 handler.  Found by Linux Verification Center (linuxtesting.org) with SVACE.  (cherry picked from commit c7071767a50a32ed727cf800ac84372429e3b4b3)",
  "id": "DEBIAN-CVE-2026-98270",
  "modified": "2026-10-07T04:47:29.596692297Z",
  "published": "2026-10-06T09:18:16.487Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-98270"
    }
  ],
  "upstream": [
    "CVE-2026-98270"
  ]
}