{"id":"AZL-106449","summary":"CVE-2026-98202 affecting package kernel 6.6.157.1-1","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nInput: synaptics-rmi4 - fix GPF in suspend and resume when unbound\n\nTransport drivers (such as rmi_i2c and rmi_spi) invoke\nrmi_driver_suspend() and rmi_driver_resume() on their child rmi_dev\ndevice during system power management events. However, transport drivers\nare fully registered and operational even if the physical RMI driver\nfailed to bind or probe the rmi_dev device.\n\nWhen rmi_driver_suspend() or rmi_driver_resume() is called on an unbound\nrmi_dev, dev_get_drvdata() returns NULL. Calling rmi_disable_irq() or\nrmi_enable_irq() without driver data attached causes a NULL pointer\ndereference and General Protection Fault when attempting to lock\ndata-\u003eenabled_mutex.\n\nFix this by checking if driver data is attached to rmi_dev in\nrmi_driver_suspend() and rmi_driver_resume(), exiting early if\nno driver data is present.","modified":"2026-10-07T14:17:08.658101498Z","published":"2026-10-06T09:18:06Z","upstream":["CVE-2026-98202"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-98202"}],"affected":[{"package":{"name":"kernel","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/kernel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"6.6.157.1-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-106449.json"}}],"schema_version":"1.9.0"}