{"id":"AZL-101306","summary":"CVE-2026-89817 affecting package kernel 6.6.150.1-1","details":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/gud: NUL-terminate TV mode names read from the device\n\ngud_connector_add_tv_mode() reads a buffer of fixed-size mode names from\nthe USB device and passes pointers into it to\ndrm_mode_create_tv_properties_legacy(), which calls strlen() on each one.\nNothing guarantees the device NUL-terminates a name, so strlen() can run\npast the end of a slot and, for the last mode, past the end of the\nallocation.\n\nTerminate each name at the end of its slot before use.","modified":"2026-09-19T05:33:49Z","published":"2026-09-16T11:16:46Z","upstream":["CVE-2026-89817"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89817"}],"affected":[{"package":{"name":"kernel","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/kernel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"6.6.150.1-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-101306.json"}}],"schema_version":"1.9.0"}