{"id":"AZL-106455","summary":"CVE-2026-98249 affecting package kernel 6.6.157.1-1","details":"In the Linux kernel, the following vulnerability has been resolved:\n\narm64: hibernate: pass HVC_SET_VECTORS args to the resume hvc\n\nswsusp_arch_suspend_exit() reinstalls the restored kernel's hyp stub\nvectors with an hvc, but never passes the arguments. x0 is not set to\nHVC_SET_VECTORS and x1 is not set to the vector address, so the stub\ndispatch falls through and returns without writing vbar_el2. EL2 is\nleft pointing at the trans_pgd copy of the vectors, a page that\nswsusp_free() releases right after resume.\n\nSet the arguments up the same way __hyp_set_vectors() does.\n\nWithout this fix, Vladimir was able to trigger a hang when resuming from\nhibernation with CONFIG_PAGE_POISONING=y and page_poison=on.","modified":"2026-10-08T05:35:32Z","published":"2026-10-06T09:18:13Z","upstream":["CVE-2026-98249"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-98249"}],"affected":[{"package":{"name":"kernel","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/kernel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"6.6.157.1-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-106455.json"}}],"schema_version":"1.9.0"}