{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "7.2.9-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  bpf: Fix out-of-bounds read of sk_protocol in bpf_sock_destroy()  sk_protocol lives in struct sock, not in struct sock_common. A timewait or request sock handed to bpf_sock_destroy() by the tcp iterator is neither, so reading sk-\u003esk_protocol runs past the object:  ================================================================== BUG: KASAN: slab-out-of-bounds in bpf_sock_destroy+0xc7/0xe0 Read of size 2 at addr ffff8881047d11b4 by task test_progs/428  Tainted: [W]=WARN Call Trace:  \u003cTASK\u003e  dump_stack_lvl+0x91/0xf0  print_report+0xd1/0x630  kasan_report+0xf3/0x130  __asan_report_load2_noabort+0x14/0x30  bpf_sock_destroy+0xc7/0xe0  bpf_prog_c3dd61f9d9cd9f37_iter_tcp6_timewait+0x9f/0xb7  bpf_iter_run_prog+0x538/0xde0  bpf_iter_tcp_seq_show+0x26b/0x4b0  bpf_seq_read+0x424/0x1210  vfs_read+0x197/0xe40  ksys_read+0x119/0x240  __x64_sys_read+0x72/0xc0  x64_sys_call+0x647/0x27e0  do_syscall_64+0xe5/0x610  entry_SYSCALL_64_after_hwframe+0x76/0x7e  Only check sk_protocol on full socks. tcp_abort() already knows how to deal with TIME_WAIT and NEW_SYN_RECV socks. Also fix the comment, it never matched the code.",
  "id": "DEBIAN-CVE-2026-98384",
  "modified": "2026-10-10T04:47:32.320422693Z",
  "published": "2026-10-09T08:16:56.940Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-98384"
    }
  ],
  "upstream": [
    "CVE-2026-98384"
  ]
}