{"id":"AZL-104448","summary":"CVE-2026-98027 affecting package kernel 6.6.157.1-1","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: dsa: mv88e6xxx: bound the policy rule dump by the caller's buffer size\n\nmv88e6xxx_get_rxnfc() uses rxnfc-\u003erule_cnt as the write index while\ndumping the policy IDR, clobbering the input value before it has been\nlooked at.  That input is the number of entries the caller had room for.\nETHTOOL_GRXCLSRLALL requires no CAP_NET_ADMIN and the ioctl sizes the\nbuffer from the rule_cnt userspace passes in, so once an admin has\ninstalled policy rules any user can ask for fewer slots than there are\nrules and run off the end of the allocation.  A rule_cnt of 0 leaves the\nbuffer pointer NULL and the walk dereferences it.\n\nCount into a local so the caller's limit survives the walk, and stop with\n-EMSGSIZE once it is reached.","modified":"2026-09-28T05:39:54Z","published":"2026-09-25T11:17:31Z","upstream":["CVE-2026-98027"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-98027"}],"affected":[{"package":{"name":"kernel","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/kernel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"6.6.157.1-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-104448.json"}}],"schema_version":"1.9.0"}