{"id":"AZL-104622","summary":"CVE-2026-98086 affecting package kernel 6.6.157.1-1","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: ump: do not touch legacy_rmidi before it exists\n\nsnd_ump_parse_endpoint() sets ump-\u003eparsed on every exit, including\nerror, before the caller attaches the legacy rawmidi device.\nump_handle_ep_name_msg() then treats parsed as \"legacy_rmidi is live\"\nand calls ump_legacy_set_rawmidi_name(), which snprintf()s into\nump-\u003elegacy_rmidi-\u003ename. If a UMP packet arrives in that window\n(IRQ path from snd_ump_receive), legacy_rmidi is still NULL\n(KASAN null-ptr-deref in snprintf).\n\nGuard the legacy helpers. parsed only means endpoint info was\nparsed, not that legacy_rmidi exists.","modified":"2026-09-28T05:39:54Z","published":"2026-09-25T11:17:38Z","upstream":["CVE-2026-98086"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-98086"}],"affected":[{"package":{"name":"kernel","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/kernel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"6.6.157.1-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-104622.json"}}],"schema_version":"1.9.0"}