{"id":"AZL-103922","summary":"CVE-2026-93210 affecting package kernel 6.6.157.1-1","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: harden DFS cache against invalid target hints\n\nCurrently, get_tgt_name() returns ERR_PTR(-ENOENT) when ce-\u003etgthint is\nNULL, and dfs_cache_noreq_update_tgthint() assumes ce-\u003etgthint is always\nvalid.\n\nIn preparation for clearing ce-\u003etgthint in free_tgts(), harden callers\nof get_tgt_name() against ERR_PTR results and harden\ndfs_cache_noreq_update_tgthint() against NULL pointer dereferences.","modified":"2026-09-25T14:16:05.195458677Z","published":"2026-09-24T16:17:15Z","upstream":["CVE-2026-93210"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-93210"}],"affected":[{"package":{"name":"kernel","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/kernel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"6.6.157.1-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-103922.json"}}],"schema_version":"1.9.0"}