Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-99500.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-99500
Upstream
Published
2026-09-04T16:18:02Z
Modified
2026-09-05T14:17:03.893605279Z
Summary
CVE-2026-80767 affecting package kernel 6.6.150.1-1
Details

In the Linux kernel, the following vulnerability has been resolved:

HID: sensor: custom: Fix use-after-free in enable_sensor

enablesensorstore() can call setpowerreportstate(), which dereferences sensorinst->powerstate and sensorinst->reportstate. These pointers refer to entries in sensorinst->fields.

Create the field attributes before exposing the enablesensor sysfs attribute, so enablesensor cannot be accessed before the state it depends on has been initialized.

On remove, delete enablesensor before freeing the field attributes, so a concurrent sysfs write cannot dereference freed memory through powerstate or report_state.

References

Affected packages

Azure Linux:3 / kernel

Package

Name
kernel
Purl
pkg:rpm/azure-linux/kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
6.6.150.1-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-99500.json"