{"id":"AZL-100856","summary":"CVE-2026-89604 affecting package kernel 6.6.150.1-1","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nefivarfs: Rate limit statfs() handler\n\nRavi reports that statfs() may be called by unprivileged users on the\nefivarfs mount point, which may result in a flood of calls to the\nQueryVariableInfo() runtime service. These calls are disproportionately\ncostly on x86 systems where the variable store is backed by SMM, as each\nSMM entry requires a rendez-vous of all the CPUs.\n\nSo rate limit the calls to QueryVariableInfo() at twice per second, and\nreturn the most recently obtained value for calls that are elided.","modified":"2026-09-13T06:06:36Z","published":"2026-09-11T20:19:45Z","upstream":["CVE-2026-89604"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89604"}],"affected":[{"package":{"name":"kernel","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/kernel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"6.6.150.1-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-100856.json"}}],"schema_version":"1.9.0"}