{"id":"AZL-100470","summary":"CVE-2026-89498 affecting package kernel 6.6.150.1-1","details":"In the Linux kernel, the following vulnerability has been resolved:\n\norangefs: fix double-free of trailer_buf on readdir copy failure\n\nOn a readdir downcall, orangefs_devreq_write_iter() frees\nop-\u003edowncall.trailer_buf with vfree() when copy_from_iter_full() fails,\nbut does not clear the pointer before goto Efault. The waiter in\ndo_readdir() is then woken with a negative status and frees the same\npointer again on its r \u003c 0 path, causing a deterministic double-free.\nA client holding /dev/pvfs2-req triggers it by sending a readdir\ndowncall whose declared trailer_size exceeds the bytes it supplies.\n\nClear the pointer after freeing so the readdir-side vfree() becomes a\nno-op.","modified":"2026-09-14T05:26:59Z","published":"2026-09-11T20:19:31Z","upstream":["CVE-2026-89498"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89498"}],"affected":[{"package":{"name":"kernel","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/kernel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"6.6.150.1-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-100470.json"}}],"schema_version":"1.9.0"}