{"id":"AZL-100737","summary":"CVE-2026-89556 affecting package kernel 6.6.150.1-1","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nmodule: validate string table section types\n\nIn elf_validity_cache_sechdrs, section sizes and offsets are validated,\nunless the section type is SHT_NULL or SHT_NOBITS.\n\nLater, elf_validity_cache_secstrings and elf_validity_cache_index_str\naccess the section name table (.shstrtab) and symbol string table\n(.strtab) headers without first ensuring that their types are\nSHT_STRTAB. If a section type is SHT_NULL or SHT_NOBITS, sh_offset has\nnot been validated and may reference out-of-bounds memory when\ndereferenced in elf_validity_cache_secstrings or\nelf_validity_cache_strtab.\n\nValidate that both string section headers are of type SHT_STRTAB before\ncaching them.","modified":"2026-09-13T06:06:36Z","published":"2026-09-11T20:19:39Z","upstream":["CVE-2026-89556"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89556"}],"affected":[{"package":{"name":"kernel","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/kernel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"6.6.150.1-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-100737.json"}}],"schema_version":"1.9.0"}