{"id":"AZL-102143","summary":"CVE-2026-92489 affecting package kernel 6.6.150.1-1","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nxfrm: Fix skb double-free in xfrm_dev_direct_output()\n\nA return value other than 1 from local_out() means that the skb has been\nconsumed or its ownership was transferred. xfrm_dev_direct_output()\nnevertheless frees the skb on this path, causing a double-free when\nnetfilter drops the packet and invalidating any other owner.\n\nReturn the local_out() result directly, matching the ownership handling\nin xfrm_output_resume().","modified":"2026-09-19T05:33:49Z","published":"2026-09-17T17:17:51Z","upstream":["CVE-2026-92489"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-92489"}],"affected":[{"package":{"name":"kernel","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/kernel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"6.6.150.1-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-102143.json"}}],"schema_version":"1.9.0"}