{"id":"AZL-106206","summary":"CVE-2026-98238 affecting package kernel 6.6.157.1-1","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: wwan: t7xx: validate the netif index in t7xx_ccmni_recv_skb()\n\nThe netif index carried in the DPMAIF PIT header is five bits wide,\nbut ccmni_inst[] only has room for NIC_DEV_MAX (21) entries.\nt7xx_ccmni_recv_skb() indexes the array without a bounds check, so\nindexes 21 to 31 read past it.  The out-of-bounds value lands in the\ncallback table that follows the array, which is never NULL, so the\nexisting !ccmni check does not catch it and the driver dereferences\nwhatever sits there as a struct t7xx_ccmni.\n\nDrop the skb when the index is out of range.\n\n\nVerified in a QEMU guest with a fault injector setting the netif\nindex to 25: the unpatched driver reads a value past ccmni_inst[],\nwhich lands in the callback table, and dereferences it far enough to\nqueue the skb.  With this check the packet is dropped.  Well-formed\ntraffic on index 0 is unaffected.\n\nChanges in v2: none.","modified":"2026-10-07T14:16:59.023701711Z","published":"2026-10-06T09:18:11Z","upstream":["CVE-2026-98238"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-98238"}],"affected":[{"package":{"name":"kernel","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/kernel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"6.6.157.1-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-106206.json"}}],"schema_version":"1.9.0"}