{"id":"AZL-103721","summary":"CVE-2026-93826 affecting package kernel 6.6.157.1-1","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nHID: hidpp: fix potential UAF in hidpp_connect_event()\n\nIf input_register_device() fails, we call input_free_device(), but keep\nstale pointer to the old device in hidpp-\u003einput, which could potentially\nlead to UAF. Fix that by resetting it to NULL before returning from\nhidpp_connect_event().","modified":"2026-09-25T14:15:45.410889803Z","published":"2026-09-24T17:17:16Z","upstream":["CVE-2026-93826"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-93826"}],"affected":[{"package":{"name":"kernel","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/kernel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"6.6.157.1-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-103721.json"}}],"schema_version":"1.9.0"}