{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "7.2.9-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  bpf: Skip unsettled links in link iterator  bpf_link_prime() inserts a link into link_idr before anon_inode_getfile() succeeds and before bpf_link_settle() publishes the ID in link-\u003eid. bpf_link_by_id() treats such an ID-zero link as unsettled, but the link iterator takes a reference without this check.  If anon_inode_getfile() then fails, the creator removes the ID and frees its still-private link directly.  The iterator is left with a dangling reference and its next bpf_link_put() accesses freed memory.  Treat ID-zero entries as transient in bpf_link_get_curr_or_next(), just as bpf_link_by_id() does.    BUG: KASAN: slab-use-after-free in bpf_link_put   Write of size 8 by task exp/384   Call Trace:   bpf_link_put                    kernel/bpf/syscall.c:3372   bpf_link_seq_next               kernel/bpf/link_iter.c:33   bpf_seq_read                    kernel/bpf/bpf_iter.c:158   vfs_read                        fs/read_write.c:572   ksys_read                       fs/read_write.c:716   do_syscall_64                   arch/x86/entry/syscall_64.c:84   entry_SYSCALL_64_after_hwframe  arch/x86/entry/entry_64.S:121   Kernel panic - not syncing: KASAN: panic_on_warn set ...",
  "id": "DEBIAN-CVE-2026-98378",
  "modified": "2026-10-10T04:47:37.037646110Z",
  "published": "2026-10-09T08:16:56.123Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-98378"
    }
  ],
  "upstream": [
    "CVE-2026-98378"
  ]
}