{"id":"AZL-101649","summary":"CVE-2026-89995 affecting package kernel 6.6.150.1-1","details":"In the Linux kernel, the following vulnerability has been resolved:\n\ndma-direct: return struct page from dma_direct_alloc_from_pool()\n\nCommit 5b138c534fda (\"dma-direct: factor out a dma_direct_alloc_from_pool\nhelper\") changed dma_direct_alloc_from_pool() to return the CPU address\nfrom dma_alloc_from_pool(). That fits dma_direct_alloc(), but\ndma_direct_alloc_pages() also uses the helper and expects a struct page *.\n\nFix this by making dma_direct_alloc_from_pool() return the struct page *\nagain, and pass the CPU address back through an out-parameter for the\ndma_direct_alloc() caller.","modified":"2026-09-17T14:15:41.514962660Z","published":"2026-09-16T11:17:10Z","upstream":["CVE-2026-89995"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89995"}],"affected":[{"package":{"name":"kernel","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/kernel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"6.6.150.1-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-101649.json"}}],"schema_version":"1.9.0"}