{"id":"AZL-100793","summary":"CVE-2026-80992 affecting package kernel 6.6.150.1-1","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: ravb: avoid dereferencing an invalid PTP clock\n\nThe PTP clock is unavailable before the first open, so querying its\nindex can dereference a NULL pointer. Registration failures can also\nleave an error pointer in priv-\u003eptp.clock.\n\nCache the PHC index separately and report -1 while no clock is\nregistered. Normalize registration errors to NULL and preserve the\nstatic timestamping capabilities.","modified":"2026-09-13T06:06:36Z","published":"2026-09-11T20:19:06Z","upstream":["CVE-2026-80992"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-80992"}],"affected":[{"package":{"name":"kernel","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/kernel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"6.6.150.1-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-100793.json"}}],"schema_version":"1.9.0"}