{"id":"AZL-104643","summary":"CVE-2026-98031 affecting package kernel 6.6.157.1-1","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nnexthop: Initialize extack in remove_nh_grp_entry()\n\nremove_nh_grp_entry() prints the extack message when a listener fails\nto replace the reduced nexthop group. However, extack is not\ninitialized and listeners are not required to set a message when\nreturning an error. Neither netdevsim nor mlxsw do so when an\nallocation fails, resulting in the dereference of an uninitialized\nstack pointer.\n\nFix by zero-initializing extack, as was done in commit 6347c5314cee\n(\"nexthop: initialize extack in nh_res_bucket_migrate()\").","modified":"2026-09-28T05:39:54Z","published":"2026-09-25T11:17:31Z","upstream":["CVE-2026-98031"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-98031"}],"affected":[{"package":{"name":"kernel","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/kernel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"6.6.157.1-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-104643.json"}}],"schema_version":"1.9.0"}