{"id":"AZL-106176","summary":"CVE-2026-98367 affecting package kernel 6.6.157.1-1","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/siw: Clear association under lock if siw_qp_modify fails in siw_accept\n\nWe need to clear cep before release state_lock as siw_qp_llp_close and\nsiw_qp_modify-\u003esiw_qp_llp_close did.\n\nOtherwise if siw_qp_modify() fails in siw_accept(), the QP's state_lock\nis released before the error path cleanup. A concurrent ibv_modify_qp()\ntransitioning the QP to ERROR can race in this window:\n\n  siw_accept()                       ibv_modify_qp(ERROR)\n  ----------------------             ----------------------\n  siw_qp_modify() fails\n  up_write(&qp-\u003estate_lock)\n                                     down_write(&qp-\u003estate_lock)\n                                     nextstate_from_idle():\n\t\t\t\t     if (qp-\u003ecep)\n                                       siw_cep_put(qp-\u003ecep) \u003c- frees cep\n                                       qp-\u003ecep = NULL\n  goto error\n    cep-\u003eqp = NULL                   \u003c- UAF\n\nClear qp-\u003ecep and drop the association reference taken by siw_cep_get(),\nall under the write lock held from the initial down_write(&qp-\u003estate_lock).\nThread B therefore sees qp-\u003ecep == NULL, skips its own put, and cannot free\nthe cep before siw_accept() is done with it.","modified":"2026-10-07T14:16:59.013246867Z","published":"2026-10-06T09:18:30Z","upstream":["CVE-2026-98367"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-98367"}],"affected":[{"package":{"name":"kernel","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/kernel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"6.6.157.1-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-106176.json"}}],"schema_version":"1.9.0"}