[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-DEBIAN-CVE-2026-64187":6},{"stargazers_count":4,"fetched_at":5},8,"2026-09-19T04:32:17.889Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":11,"aliases":12,"duplicate_of":9,"upstream":13,"downstream":16,"duplicates":17,"related":18,"reserved_at":9,"published_at":19,"modified_at":20,"state":9,"summary":21,"references_raw":23,"kevs":30,"epss":9,"epss_history":31,"metrics":32,"affected":33},"DEBIAN-CVE-2026-64187","In the Linux kernel, the following vulnerability has been resolved:  xfs: fail recovery on a committed log item with no regions  If the first op of a transaction is a bare transaction header (len == sizeof(struct xfs_trans_header)), xlog_recover_add_to_trans() adds an item but no region, leaving it on r_itemq with ri_cnt == 0 and ri_buf == NULL.  The header can be split across op records, so later ops may still add regions; the item is only invalid if the transaction commits with none. The runtime commit path never emits such a transaction, so this only happens on a crafted log.  It came from an AI-assisted code audit of the recovery parser.  xlog_recover_reorder_trans() calls ITEM_TYPE() on the item, which reads *(unsigned short *)item->ri_buf[0].iov_base and faults on the NULL ri_buf.  Reject it there, before the commit handlers that also read ri_buf[0].   KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007]  RIP: 0010:xlog_recover_reorder_trans (fs/xfs/xfs_log_recover.c:1836)   xlog_recover_commit_trans (fs/xfs/xfs_log_recover.c:2043)   xlog_recover_process_data (fs/xfs/xfs_log_recover.c:2501)   xlog_do_recovery_pass (fs/xfs/xfs_log_recover.c:3244)   xlog_recover (fs/xfs/xfs_log_recover.c:3493)   xfs_log_mount (fs/xfs/xfs_log.c:618)   xfs_mountfs (fs/xfs/xfs_mount.c:1034)   xfs_fs_fill_super (fs/xfs/xfs_super.c:1938)   vfs_get_tree (fs/super.c:1695)   path_mount (fs/namespace.c:4161)   __x64_sys_mount (fs/namespace.c:4367)",null,[],[],[],[14],{"_key":15},"CVE-2026-64187",[],[],[],"2026-07-20T17:18:21.743Z","2026-07-21T15:00:17.685419215Z",{"cisa_kev":22,"cisa_ransomware":22,"cisa_vendor":9,"epss_severity":9,"epss_score":9,"severity":9,"severity_score":9,"severity_version":9,"severity_source":9,"severity_vector":9,"severity_status":9},false,[24],{"url":25,"sources":26,"tags":28},"https://security-tracker.debian.org/tracker/CVE-2026-64187",[27],"osv_debian",[29],"Advisory",[],[],[],[34],{"ecosystem":35,"name":36,"vendor":37,"product":36,"cpe_part":9,"purl_type":38,"purl_namespace":37,"purl_name":36,"source":9,"versions":39},"Debian","linux","debian","deb",[40,44,45,49],{"version":41,"is_range":42,"range_type":43,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"all",true,"ecosystem",{"version":41,"is_range":42,"range_type":43,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},{"version":46,"is_range":42,"range_type":43,"version_start":9,"version_start_type":9,"version_end":47,"version_end_type":48,"fixed_in":9},"lt6_12_96_1","6.12.96-1","excluding",{"version":41,"is_range":42,"range_type":43,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9}]