{"id":"AZL-104304","summary":"CVE-2026-98003 affecting package kernel 6.6.157.1-1","details":"In the Linux kernel, the following vulnerability has been resolved:\n\niommu/amd: Do not reallocate GA log buffers on resume\n\nCommit c5e1a1eb9279 (\"iommu/amd: Simplify and Consolidate Virtual APIC\n(AVIC) Enablement\") moved the GA log allocation from iommu_init_pci()\nto enable_iommus_vapic(), which is called on every resume.\n\niommu_init_ga_log() assigns iommu-\u003ega_log and iommu-\u003ega_log_tail\nunconditionally. Each resume therefore replaces the boot-time pointers\nand leaks both old allocations. The function also uses GFP_KERNEL from a\nsyscore resume callback, where interrupts are disabled and the non-boot\nCPUs are offline.\n\nReturn early if both buffers are already allocated. Clear the pointers\nin free_ga_log() so a partial allocation failure cannot leave ga_log\ndangling.","modified":"2026-09-27T05:34:32Z","published":"2026-09-25T11:17:28Z","upstream":["CVE-2026-98003"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-98003"}],"affected":[{"package":{"name":"kernel","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/kernel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"6.6.157.1-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-104304.json"}}],"schema_version":"1.9.0"}