{"id":"AZL-100842","summary":"CVE-2026-89470 affecting package kernel 6.6.150.1-1","details":"In the Linux kernel, the following vulnerability has been resolved:\n\npower: supply: cros_usbpd: Limit port counts to EC_USB_PD_MAX_PORTS\n\nCurrently the cros_usbpd-charger driver probe iterates based on raw\ncharger port count returned by the embedded controller. The only check\nis against the number of USB PD ports which the embedded controller\nalso defines. A malicious embedded controller could return an inaccurate\nport count (up to 255) resulting in an out of bounds write and\nsubsequent memory corruption.\n\nUpdate helper functions in cros_usbpd-charger to limit port counts to\nEC_USB_PD_MAX_PORTS.","modified":"2026-09-12T14:15:33.083745682Z","published":"2026-09-11T20:19:28Z","upstream":["CVE-2026-89470"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89470"}],"affected":[{"package":{"name":"kernel","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/kernel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"6.6.150.1-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-100842.json"}}],"schema_version":"1.9.0"}