{"id":"AZL-85530","summary":"CVE-2026-30656 affecting package fio for versions less than 3.37-4","details":"A NULL pointer dereference vulnerability exists in fio (Flexible I/O Tester) v3.41 when parsing job files containing the fdp_pli option. The callback function str_fdp_pli_cb() does not validate the input pointer and calls strdup() on a NULL value when the option is specified without an argument. This results in a segmentation fault and process crash.","modified":"2026-08-30T05:26:50Z","published":"2026-04-16T15:17:17Z","upstream":["CVE-2026-30656"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-30656"}],"affected":[{"package":{"name":"fio","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/fio"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.37-4"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-85530.json"}}],"schema_version":"1.9.0"}