{"id":"AZL-105729","summary":"CVE-2026-15390 affecting package qemu 10.1.0-1","details":"Das U-Boot with CONFIG_IP_DEFRAG=y parameter fails to clear IP reassembly state after delivering a complete datagram. An attacker who can deliver fragmented IP traffic can execute arbitrary code by sending duplicated last-fragment IP packets.\n\n\nThis issue was fixed in commit b1aec609bb5e0d08c25c888c91935287ab4ee5fa in version 2026.07.","modified":"2026-10-05T05:34:30Z","published":"2026-09-29T10:17:11Z","upstream":["CVE-2026-15390"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-15390"}],"affected":[{"package":{"name":"qemu","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/qemu"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"10.1.0-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-105729.json"}}],"schema_version":"1.9.0"}