{"id":"AZL-101136","summary":"CVE-2026-89822 affecting package kernel 6.6.150.1-1","details":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/i915: Guard against NULL driver_data in i915_pci_probe()\n\npci_match_device() can return the dummy pci_device_id_any entry\nwhen a device is force-bound via sysfs driver_override, in which\ncase -\u003edriver_data is unset (NULL). i915_pci_probe() casts it to\nstruct intel_device_info * unconditionally and dereferences\nintel_info-\u003erequire_force_probe, causing a NULL-ptr-deref.\n\n(cherry picked from commit 2727922084672cc274ecea726ea00363c2893731)","modified":"2026-09-18T05:37:08Z","published":"2026-09-16T11:16:47Z","upstream":["CVE-2026-89822"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89822"}],"affected":[{"package":{"name":"kernel","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/kernel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"6.6.150.1-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-101136.json"}}],"schema_version":"1.9.0"}