{"id":"AZL-103598","summary":"CVE-2026-93272 affecting package kernel 6.6.157.1-1","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nremoteproc: qcom_wcnss: Fix handling the lack of PD regulators in v3\n\nThe changes introduced to handle single power domain platforms have\nswapped the info pointer increment from num_pd_vregs to num_pds, which\nwould shift the info pointer past the end of the array for pronto-v3,\nwhich does not list power domain regulators in vregs.\n\nThis showed up as a difference between GCC- and LLVM-compiled kernels\non SDM632 devices, where only with LLVM one would get the\n\"regulator request with no identifier\" error, because the out-of-bounds\nmemory ended up being zeroed. Fix by skipping the increment when there\nare more power domains than regulators.","modified":"2026-09-25T14:15:43.352449851Z","published":"2026-09-24T16:17:24Z","upstream":["CVE-2026-93272"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-93272"}],"affected":[{"package":{"name":"kernel","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/kernel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"6.6.157.1-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-103598.json"}}],"schema_version":"1.9.0"}