{"id":"AZL-100623","summary":"CVE-2026-89765 affecting package kernel 6.6.150.1-1","details":"In the Linux kernel, the following vulnerability has been resolved:\n\ntimers/itimer: Zero-init old itimerval before copy to userspace\n\nOn native sparc64, struct __kernel_old_timeval contains a four-byte hole\nafter tv_usec because tv_sec is 64-bit while __kernel_suseconds_t is 32-bit.\nput_itimerval() fills only the named fields in a stack-allocated\n__kernel_old_itimerval and copies the entire object to userspace, so\ngetitimer() can expose the two padding holes.\n\nZero-initialize the aggregate before assigning the fields so implicit\npadding is deterministic before it crosses the user/kernel boundary.","modified":"2026-09-13T06:06:36Z","published":"2026-09-11T20:20:07Z","upstream":["CVE-2026-89765"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89765"}],"affected":[{"package":{"name":"kernel","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/kernel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"6.6.150.1-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-100623.json"}}],"schema_version":"1.9.0"}