{"id":"AZL-106020","summary":"CVE-2026-98362 affecting package kernel 6.6.157.1-1","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nclk: scpi: bound-check DVFS index in scpi_dvfs_recalc_rate\n\ndvfs_get_idx() may return an out-of-range index if the SCP firmware is\nbuggy or returns a stale value. Only negative indexes were rejected, so a\nlarge index walked past info-\u003eopps and could treat garbage as a clock rate\n(KASAN OOB / wrong frequency to consumers). The missing upper bound dates\nback to the original SCPI clock driver.\n\nTreat indexes \u003e= opp count as invalid and return 0, same as idx \u003c 0.","modified":"2026-10-07T14:16:55.001951114Z","published":"2026-10-06T09:18:30Z","upstream":["CVE-2026-98362"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-98362"}],"affected":[{"package":{"name":"kernel","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/kernel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"6.6.157.1-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-106020.json"}}],"schema_version":"1.9.0"}