{"id":"AZL-100539","summary":"CVE-2026-89717 affecting package kernel 6.6.150.1-1","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nzram: set default primary compressor in zram_destroy_comps()\n\nPatch series \"zram: fix zram issues reported by sashiko\".\n\nSashiko drove by and reported [1] a couple of zram issues:\na possible BUG_ON() in zlib code due to missing winbits range\nvalidation and one possible NULL-ptr dereference in zcomp.\nBoth are low risk yet still worth fixing.\n\n\nThis patch (of 2):\n\nzram_destroy_comps() resets all compressors and leaves them set to NULL,\nincluding the primary one, which is invalid device state, as now\ncomp_algorithm_show()-\u003estrcmp() can be called on a NULL compressor.  Set\ndefault primary compressor in zram_destroy_comps().","modified":"2026-09-13T06:06:36Z","published":"2026-09-11T20:19:59Z","upstream":["CVE-2026-89717"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89717"}],"affected":[{"package":{"name":"kernel","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/kernel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"6.6.150.1-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-100539.json"}}],"schema_version":"1.9.0"}