{"id":"AZL-103715","summary":"CVE-2026-97511 affecting package kernel 6.6.157.1-1","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mac80211: avoid out-of-bounds access in monitor\n\nIn NAN, we don't know on what band the frame will be sent. Therefore we\nset info-\u003eband to NUM_NL80211_BANDS. However, this leads to out-of-bound\naccess in ieee80211_add_tx_radiotap_header when we try to access the\nsbands array.\n\nFix it by not accessing the array if the band is NUM_NL80211_BANDS.\nThis means that we will not report rate info for legacy rate in NAN.\nBut nobody really cares about it.","modified":"2026-09-25T14:15:45.059158935Z","published":"2026-09-24T17:17:28Z","upstream":["CVE-2026-97511"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-97511"}],"affected":[{"package":{"name":"kernel","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/kernel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"6.6.157.1-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-103715.json"}}],"schema_version":"1.9.0"}