{"id":"AZL-103676","summary":"CVE-2026-93286 affecting package kernel 6.6.157.1-1","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: appletalk: fix NULL pointer dereference in aarp_send_ddp()\n\naarp_send_ddp() calls atalk_find_dev_addr(dev) in the LocalTalk fast\npath without checking for NULL. When the device has no AppleTalk\ninterface configured (dev-\u003eatalk_ptr == NULL), this leads to a NULL\npointer dereference at the at-\u003es_net access.\n\n KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007]\n RIP: 0010:aarp_send_ddp (net/appletalk/aarp.c:552 (discriminator 2))\n Call Trace:\n  \u003cTASK\u003e\n  atalk_sendmsg (net/appletalk/ddp.c:1715)\n  __sys_sendto (net/socket.c:2265 (discriminator 1))\n  __x64_sys_sendto (net/socket.c:2272)\n  do_syscall_64 (arch/x86/entry/syscall_64.c:94)\n  entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)\n\nAdd a NULL check consistent with the other callers of\natalk_find_dev_addr().","modified":"2026-09-26T05:34:12Z","published":"2026-09-24T17:17:09Z","upstream":["CVE-2026-93286"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-93286"}],"affected":[{"package":{"name":"kernel","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/kernel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"6.6.157.1-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-103676.json"}}],"schema_version":"1.9.0"}