{"id":"AZL-103961","summary":"CVE-2026-97519 affecting package kernel 6.6.157.1-1","details":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/xe: Fix null pointer dereference in devcoredump cleanup\n\nIn xe_devcoredump_snapshot_free(), ss-\u003egt may be NULL when the snapshot\nwas never fully populated (e.g., when cleanup is triggered without a\nprior capture). Guard the xe_guc_capture_put_matched_nodes() call with\nIS_ERR_OR_NULL() to prevent a null dereference.\n\nIn xe_devcoredump_free(), the deferred work is only queued when a\ncoredump is captured, so guard cancel_work_sync() with a check on\ncoredump-\u003ecaptured.","modified":"2026-09-25T14:15:57.145728276Z","published":"2026-09-24T17:17:29Z","upstream":["CVE-2026-97519"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-97519"}],"affected":[{"package":{"name":"kernel","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/kernel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"6.6.157.1-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-103961.json"}}],"schema_version":"1.9.0"}