{"id":"AZL-106413","summary":"CVE-2026-98270 affecting package kernel 6.6.157.1-1","details":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: check ras and obj before dereference\n\nnbio_v7_9_handle_ras_controller_intr_no_bifring() dereferences ras and obj\nwithout checking either for NULL. Both amdgpu_ras_get_context() and\namdgpu_ras_find_obj() can return NULL, e.g. during the window between\nadev-\u003enbio.ras being set (early in amdgpu_ras_init(), by design, to\nenable the fatal-error interrupt as soon as possible) and the PCIE_BIF\nras object actually being created in RAS late_init. Any interrupt in that\nwindow crashes in hard-IRQ context.\n\nThis is analogous to commit d190b459b2a4 (\"drm/amdgpu: the warning\ndereferencing obj for nbio_v7_4\"), which fixed the same issue in the\nnbio_v7_4 handler.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.\n\n(cherry picked from commit c7071767a50a32ed727cf800ac84372429e3b4b3)","modified":"2026-10-08T05:35:32Z","published":"2026-10-06T09:18:16Z","upstream":["CVE-2026-98270"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-98270"}],"affected":[{"package":{"name":"kernel","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/kernel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"6.6.157.1-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-106413.json"}}],"schema_version":"1.9.0"}