{"id":"AZL-106104","summary":"CVE-2026-98172 affecting package kernel 6.6.157.1-1","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: fix smbd_connection leak on cifs_get_tcp_session() error\n\nWhen an RDMA connection is successfully established via\nsmbd_get_connection() but cifs_get_tcp_session() later fails (e.g.\nkthread_create() returns an error), the error path frees tcp_ses\nwithout first destroying the smbd_connection.\n\nFix this by calling smbd_destroy() in the out_err cleanup path before\nkfree(tcp_ses).  smbd_destroy() safely handles the case where\nsmbd_conn is NULL, so it can be called unconditionally.","modified":"2026-10-08T05:35:32Z","published":"2026-10-06T09:17:58Z","upstream":["CVE-2026-98172"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-98172"}],"affected":[{"package":{"name":"kernel","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/kernel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"6.6.157.1-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-106104.json"}}],"schema_version":"1.9.0"}