{"id":"AZL-101538","summary":"CVE-2026-89924 affecting package kernel 6.6.150.1-1","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: s390: Fix old_data leak in guest debug error path\n\n__import_wp_info() allocates a per-watchpoint old_data buffer to back up\nthe original guest memory contents. If a later watchpoint of the same\nKVM_SET_GUEST_DEBUG request fails to import, kvm_s390_import_bp_data()\njumps to the error label, which frees the wp_info array but not the\nold_data buffers of the entries that were imported successfully. Up to\nMAX_BP_COUNT - 1 buffers of up to MAX_WP_SIZE bytes are leaked per failed\nrequest, and the request can be repeated.\n\nCreate error handling for cleaning up all created old_data memory\nareas.","modified":"2026-09-17T14:15:58.937978899Z","published":"2026-09-16T11:17:01Z","upstream":["CVE-2026-89924"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89924"}],"affected":[{"package":{"name":"kernel","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/kernel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"6.6.150.1-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-101538.json"}}],"schema_version":"1.9.0"}