{"id":"AZL-101355","summary":"CVE-2026-89794 affecting package kernel 6.6.150.1-1","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: zero pipe read compound padding\n\nCompound response handling extends the last response iov to an eight-byte\nboundary.\n\nsmb2_read_pipe() allocates only the payload size, so the alignment padding\ncan expose up to seven bytes of uninitialized kernel heap memory.\n\nAllocate the aligned size and clear the unused tail before pinning the\nresponse buffer.","modified":"2026-09-17T14:15:48.818928098Z","published":"2026-09-16T11:16:44Z","upstream":["CVE-2026-89794"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89794"}],"affected":[{"package":{"name":"kernel","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/kernel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"6.6.150.1-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-101355.json"}}],"schema_version":"1.9.0"}