{"id":"AZL-104364","summary":"CVE-2026-97998 affecting package kernel 6.6.157.1-1","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nfnetlink_log: cope with concurrent instance destruction\n\nInstances are refcounted. However, only memory release happens on the\n1 -\u003e 0 transition; the unlink from hashes can occur with any refcount.\n\nUncooperative userspace can force a situation where a queue is pending\nfor destruction from netlink event while a different socket with same\nportid processes an UNBIND request.\n\nWith right timing, this will unhash the instance again:\n\nOops: general protection fault, [..]\nCall Trace:\n \u003cTASK\u003e\n nfulnl_recv_config+0x31a/0xd50\n nfnetlink_rcv_msg+0x7c2/0xeb0","modified":"2026-09-27T05:34:32Z","published":"2026-09-25T11:17:28Z","upstream":["CVE-2026-97998"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-97998"}],"affected":[{"package":{"name":"kernel","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/kernel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"6.6.157.1-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-104364.json"}}],"schema_version":"1.9.0"}