{"id":"DEBIAN-CVE-2026-98259","details":"In the Linux kernel, the following vulnerability has been resolved:  fs/dax: check zero or empty entry before converting xarray entry  Calling dax_to_folio() with empty entry causes kernel panic below when booting a VM with DAX enabled storage.  This patch checks empty entry before calling dax_to_folio() on dax_associate_entry(), dax_disassociate_entry(), and dax_busy_page().  Commit 98c183a4fccf (\"fs/dax: don't disassociate zero page entries\") added guards in the associate and disassociate paths, but the guards still come after dax_to_folio(), and dax_busy_page() still has the same problem.  [    0.737679] EXT4-fs (pmem0p1): mounted filesystem 79676804-7c8b-491a-b2a6-9bae3c72af70 ro with ordered data mode. Quota mode: disabled. [    0.737891] VFS: Mounted root (ext4 filesystem) readonly on device 259:1. [    0.739119] devtmpfs: mounted [    0.739476] Freeing unused kernel memory: 1920K [    0.740156] Run /sbin/init as init process [    0.740229]   with arguments: [    0.740286]     /sbin/init [    0.740321]   with environment: [    0.740369]     HOME=/ [    0.740400]     TERM=linux [    0.743162] Unable to handle kernel paging request at virtual address fffffdffbf000008 [    0.743285] Mem abort info: [    0.743316]   ESR = 0x0000000096000006 [    0.743371]   EC = 0x25: DABT (current EL), IL = 32 bits [    0.743444]   SET = 0, FnV = 0 [    0.743489]   EA = 0, S1PTW = 0 [    0.743545]   FSC = 0x06: level 2 translation fault [    0.743610] Data abort info: [    0.743656]   ISV = 0, ISS = 0x00000006, ISS2 = 0x00000000 [    0.743720]   CM = 0, WnR = 0, TnD = 0, TagAccess = 0 [    0.743785]   GCS = 0, Overlay = 0, DirtyBit = 0, Xs = 0 [    0.743848] swapper pgtable: 4k pages, 48-bit VAs, pgdp=00000000b9d17000 [    0.743931] [fffffdffbf000008] pgd=10000000bfa3d403, p4d=10000000bfa3d403, pud=1000000040bfe403, pmd=0000000000000000 [    0.744070] Internal error: Oops: 0000000096000006 [#1]  SMP [    0.748888] CPU: 0 UID: 0 PID: 1 Comm: init Not tainted 6.18.4 #1 NONE [    0.749421] pstate: 004000c5 (nzcv daIF +PAN -UAO -TCO -DIT -SSBS BTYPE=--) [    0.749969] pc : dax_disassociate_entry.constprop.0+0x20/0x50 [    0.750444] lr : dax_insert_entry+0xcc/0x408 [    0.750802] sp : ffff80008000b9e0 [    0.751083] x29: ffff80008000b9e0 x28: 0000000000000000 x27: 0000000000000000 [    0.751682] x26: 0000000001963d01 x25: ffff0000004f7d90 x24: 0000000000000000 [    0.752264] x23: 0000000000000000 x22: ffff80008000bcc8 x21: 0000000000000011 [    0.752836] x20: ffff80008000ba90 x19: 0000000001963d01 x18: 0000000000000000 [    0.753407] x17: 0000000000000000 x16: 0000000000000000 x15: 0000000000000000 [    0.753970] x14: ffffbf3154b9ae70 x13: 0000000000000000 x12: ffffbf3154b9ae70 [    0.754548] x11: ffffffffffffffff x10: 0000000000000000 x9 : 0000000000000000 [    0.755122] x8 : 000000000000000d x7 : 000000000000001f x6 : 0000000000000000 [    0.755707] x5 : 0000000000000000 x4 : 0000000000000000 x3 : fffffdffc0000000 [    0.756287] x2 : 0000000000000008 x1 : 0000000040000000 x0 : fffffdffbf000000 [    0.756871] Call trace: [    0.757107]  dax_disassociate_entry.constprop.0+0x20/0x50 (P) [    0.757592]  dax_iomap_pte_fault+0x4fc/0x808 [    0.757951]  dax_iomap_fault+0x28/0x30 [    0.758258]  ext4_dax_huge_fault+0x80/0x2dc [    0.758594]  ext4_dax_fault+0x10/0x3c [    0.758892]  __do_fault+0x38/0x12c [    0.759175]  __handle_mm_fault+0x530/0xcf0 [    0.759518]  handle_mm_fault+0xe4/0x230 [    0.759833]  do_page_fault+0x17c/0x4dc [    0.760144]  do_translation_fault+0x30/0x38 [    0.760483]  do_mem_abort+0x40/0x8c [    0.760771]  el0_ia+0x4c/0x170 [    0.761032]  el0t_64_sync_handler+0xd8/0xdc [    0.761371]  el0t_64_sync+0x168/0x16c [    0.761677] Code: f9453021 f2dfbfe3 cb813080 8b001860 (f9400401) [    0.762168] ---[ end trace 0000000000000000 ]--- [    0.762550] note: init[1] exited with irqs disabled [    0.762631] Kernel panic - not syncing: Attempted to kill init! exitcode=0x0000000b","modified":"2026-10-07T05:00:30.073493628Z","published":"2026-10-06T09:18:14.877Z","upstream":["CVE-2026-98259"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2026-98259"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.2.8-1"}]}],"versions":["6.12.100-1","6.12.101-1","6.12.105-1","6.12.107-1","6.12.111-1","6.12.38-1","6.12.41-1","6.12.43-1","6.12.43-1~bpo12+1","6.12.48-1","6.12.57-1","6.12.57-1~bpo12+1","6.12.63-1","6.12.63-1~bpo12+1","6.12.69-1","6.12.69-1~bpo12+1","6.12.73-1","6.12.73-1~bpo12+1","6.12.74-1","6.12.74-2","6.12.74-2~bpo12+1","6.12.85-1","6.12.85-1~bpo12+1","6.12.86-1","6.12.86-1~bpo12+1","6.12.88-1","6.12.88-1~bpo12+1","6.12.90-1","6.12.90-1~bpo12+1","6.12.90-2","6.12.90-2~bpo12+1","6.12.94-1","6.12.94-1~bpo12+1","6.12.95-1","6.12.95-1~bpo12+1","6.12.96-1","6.13.10-1~exp1","6.13.11-1~exp1","6.13.2-1~exp1","6.13.3-1~exp1","6.13.4-1~exp1","6.13.5-1~exp1","6.13.6-1~exp1","6.13.7-1~exp1","6.13.8-1~exp1","6.13.9-1~exp1","6.13~rc6-1~exp1","6.13~rc7-1~exp1","6.14.3-1~exp1","6.14.5-1~exp1","6.14.6-1~exp1","6.15-1~exp1","6.15.1-1~exp1","6.15.2-1~exp1","6.15.3-1~exp1","6.15.4-1~exp1","6.15.5-1~exp1","6.15.6-1~exp1","6.15~rc7-1~exp1","6.16-1~exp1","6.16.1-1~exp1","6.16.10-1","6.16.11-1","6.16.12-1","6.16.12-1~bpo13+1","6.16.12-2","6.16.3-1","6.16.3-1~bpo13+1","6.16.5-1","6.16.6-1","6.16.7-1","6.16.8-1","6.16.9-1","6.16~rc7-1~exp1","6.17.10-1","6.17.11-1","6.17.12-1","6.17.13-1","6.17.13-1~bpo13+1","6.17.2-1~exp1","6.17.5-1~exp1","6.17.6-1","6.17.7-1","6.17.7-2","6.17.8-1","6.17.8-1~bpo13+1","6.17.9-1","6.18.1-1~exp1","6.18.10-1","6.18.12-1","6.18.12-1~bpo13+1","6.18.13-1","6.18.14-1","6.18.15-1","6.18.15-1~bpo13+1","6.18.2-1~exp1","6.18.3-1","6.18.5-1","6.18.5-1~bpo13+1","6.18.8-1","6.18.9-1","6.18.9-1~bpo13+1","6.18~rc4-1~exp1","6.18~rc4-1~exp2","6.18~rc5-1~exp1","6.18~rc6-1~exp1","6.18~rc7-1~exp1","6.19-1~exp1","6.19.10-1","6.19.10-1~bpo13+1","6.19.11-1","6.19.11-1~bpo13+1","6.19.12-1","6.19.13-1","6.19.13-1~bpo13+1","6.19.14-1","6.19.14-1~bpo13+1","6.19.2-1~exp1","6.19.3-1~exp1","6.19.4-1~exp1","6.19.5-1~exp1","6.19.6-1","6.19.6-2","6.19.6-2~bpo13+1","6.19.8-1","6.19.8-1~bpo13+1","6.19~rc4-1~exp1","6.19~rc5-1~exp1","6.19~rc6-1~exp1","6.19~rc7-1~exp1","6.19~rc8-1~exp1","7.0-1~exp1","7.0.1-1~exp1","7.0.10-1","7.0.10-1~bpo13+1","7.0.12-1","7.0.12-2","7.0.12-2~bpo13+1","7.0.13-1","7.0.13-1~bpo13+1","7.0.14-1","7.0.3-1","7.0.4-1","7.0.4-1~bpo13+1","7.0.7-1","7.0.7-1~bpo13+1","7.0.9-1","7.0.9-1~bpo13+1","7.1.1-1~exp1","7.1.10-1","7.1.12-1","7.1.13-1","7.1.13-1~bpo13+1","7.1.2-1~exp1","7.1.3-1","7.1.3-1+sunvdc","7.1.3-1~bpo13+1","7.1.4-1","7.1.5-1","7.1.6-1","7.1.7-1","7.1.7-1~bpo13+1","7.1.8-1","7.1.8-1~bpo13+1","7.1.8-2","7.1.9-1","7.1.9-1+sparc64","7.1~rc2-1~exp1","7.1~rc3-1~exp1","7.1~rc4-1~exp1","7.1~rc4-1~exp2","7.1~rc5-1~exp1","7.1~rc7-1~exp1","7.2.2-1~exp1","7.2.3-1~exp1","7.2.6-1","7.2.6-1~bpo13+1","7.2.7-1","7.2~rc3-1~exp1","7.2~rc5-1~exp1","7.2~rc7-1~exp1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-98259.json"}}],"schema_version":"1.9.0"}