<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Kernel-Security on ZX Cloud Security</title><link>https://zxcloudsecurity.co.uk/tags/kernel-security/</link><description>Recent content in Kernel-Security on ZX Cloud Security</description><generator>Hugo</generator><language>en-GB</language><lastBuildDate>Tue, 18 Jun 2024 08:49:51 +0000</lastBuildDate><atom:link href="https://zxcloudsecurity.co.uk/tags/kernel-security/index.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2026-46292: Linux Kernel pmdomain Flaw in Azure</title><link>https://zxcloudsecurity.co.uk/posts/cve-2026-46292-linux-kernel-pmdomain-genpd-azure/</link><pubDate>Thu, 18 Jun 2026 08:49:51 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/cve-2026-46292-linux-kernel-pmdomain-genpd-azure/</guid><description>CVE-2026-46292 is a Linux kernel pmdomain/genpd vulnerability affecting Azure Linux VMs. Learn the security impact and recommended mitigations.</description><content:encoded><![CDATA[<p>🟡 <strong>Medium</strong>  |  <strong>Source:</strong> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-46292">Microsoft Security Response Center</a></p>
<hr>
<p>CVE-2026-46292 is a Linux kernel vulnerability affecting the power management domain (pmdomain) subsystem, specifically a flaw in the detach procedure for virtual devices within the Generic Power Domain (genpd) framework. While published via Microsoft&rsquo;s Security Response Centre in the context of Azure, this is a kernel-level issue that could affect Linux-based virtual machines and container hosts. Improper handling of virtual device detachment may lead to memory corruption or instability, with potential security implications depending on exploitability.</p>
<blockquote>
<p><strong>Security Architect&rsquo;s Take:</strong> Review whether your Azure Linux VM or AKS node pool images are running kernel versions affected by this flaw, and prioritise patching through your standard OS update pipeline or by adopting Microsoft&rsquo;s latest endorsed Linux images. If you operate workloads with elevated kernel exposure — such as nested virtualisation or custom kernel modules — treat this with heightened urgency.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-46292">CVE-2026-46292 pmdomain: core: Fix detach procedure for virtual devices in genpd</a></p>
]]></content:encoded></item></channel></rss>