{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "7.2.9-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  veth: manage XDP program pointers during channel resize  veth_set_channels() tears down XDP resources for removed RX queues without clearing rq-\u003exdp_prog.  If the program is then detached or replaced, those queues keep the old pointer after bpf_prog_put(). A later channel increase can re-enable NAPI and run the freed program.    BUG: unable to handle page fault for address: ffffc90000256048   Oops: Oops: 0000 [#1] SMP KASAN NOPTI   RIP: veth_xdp_rcv_skb (include/linux/filter.h:779                          include/net/xdp.h:696 drivers/net/veth.c:820)   Call Trace:    veth_xdp_rcv (drivers/net/veth.c:941)    veth_poll (drivers/net/veth.c:986)    __napi_poll (net/core/dev.c:7787)    net_rx_action (net/core/dev.c:7850 net/core/dev.c:8007)    handle_softirqs (kernel/softirq.c:645)   Kernel panic - not syncing: Fatal exception in interrupt",
  "id": "DEBIAN-CVE-2026-98381",
  "modified": "2026-10-10T04:47:24.718721870Z",
  "published": "2026-10-09T08:16:56.547Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-98381"
    }
  ],
  "upstream": [
    "CVE-2026-98381"
  ]
}