{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "7.2.9-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  net/sched: reject IDR error pointers when deleting actions  tcf_action_delete() drops the reference held by its lookup before calling tcf_idr_delete_index() with the saved action index.  An unlocked classifier can remove that action and reserve the same IDR slot with ERR_PTR(-EBUSY) in between.  tcf_idr_delete_index() only checks the lookup result for NULL.  It therefore treats the reservation as a tc_action and dereferences tcfa_bindcnt.  A hardware execution breakpoint was used to schedule the interleaving without changing the kernel source.  KASAN reported this decoded trace:    BUG: KASAN: null-ptr-deref in tca_action_gd+0x5b9/0x1010   Read of size 4 at addr 0000000000000010 by task poc/150   Oops: general protection fault, probably for non-canonical address 0xdffffc0000000002   RIP: tca_action_gd+0x5c0/0x1010:     arch_atomic_read at arch/x86/include/asm/atomic.h:23     raw_atomic_read at include/linux/atomic/atomic-arch-fallback.h:457     atomic_read at include/linux/atomic/atomic-instrumented.h:33     tcf_idr_delete_index at net/sched/act_api.c:766     tcf_action_delete at net/sched/act_api.c:1859     tcf_del_notify at net/sched/act_api.c:2014     tca_action_gd at net/sched/act_api.c:2064   R13: 0000000000000010 R15: fffffffffffffff0   Kernel panic - not syncing: Fatal exception  R15 contains ERR_PTR(-EBUSY), and adding the tcfa_bindcnt offset produces the address in R13.  With the guard applied, the same reproducer returned -ENOENT without a KASAN report or panic.  Treat error pointers as absent and return -ENOENT.",
  "id": "DEBIAN-CVE-2026-98380",
  "modified": "2026-10-10T04:47:25.969417931Z",
  "published": "2026-10-09T08:16:56.400Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-98380"
    }
  ],
  "upstream": [
    "CVE-2026-98380"
  ]
}