{"id":"AZL-104519","summary":"CVE-2026-98019 affecting package kernel 6.6.157.1-1","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: mark a NULL call argument precise\n\ncheck_func_arg() allows bpf_register_is_null() for nullable arguments\nw/o marking the underlying scalar register precise. Hence a checkpoint\ncreated on such a path would prune against arbitrary scalar value.\n\ncheck_helper_call() enforces second parameter of the\nbpf_get_local_storage() to be zero, w/o marking the underlying scalar\nregister precise. Hence a checkpoint created on such a path would\nprune against arbitrary scalar value.\n\nGrouping these two into one patch, as they share the same fixes tag.","modified":"2026-09-30T05:39:58Z","published":"2026-09-25T11:17:30Z","upstream":["CVE-2026-98019"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-98019"}],"affected":[{"package":{"name":"kernel","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/kernel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"6.6.157.1-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-104519.json"}}],"schema_version":"1.9.0"}