{"id":"AZL-104457","summary":"CVE-2026-98017 affecting package kernel 6.6.157.1-1","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: defer qdisc freeing after failed creation\n\nAn RTM_NEWQDISC request can make clsact bind a populated shared ingress\nblock during -\u003einit(), publishing an embedded mini_Qdisc to lockless\nreaders.  If the same request has an invalid TCA_RATE, estimator setup\nfails after -\u003einit(); the unwind removes the pointer but synchronously\nfrees its containing qdisc while tc_run() may still hold it.\n\nRetire failed qdiscs through the same RCU helper as normal destruction.\nInline the synchronous free into the callback now that no direct callers\nremain.","modified":"2026-09-26T14:16:13.287751770Z","published":"2026-09-25T11:17:30Z","upstream":["CVE-2026-98017"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-98017"}],"affected":[{"package":{"name":"kernel","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/kernel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"6.6.157.1-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-104457.json"}}],"schema_version":"1.9.0"}