{"id":"AZL-106209","summary":"CVE-2026-98355 affecting package kernel 6.6.157.1-1","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/rtrs: guard against null kobj name\n\nIn the client, if `init_path()` errors, the callee tries to clean up\nwith `rtrs_clt_close_conns()`. However, this can lead to calling the\nevent tracing code with `clt_path-\u003ekobj-\u003ename` being `NULL` and thus\ncausing a null pointer dereference when trying to copy from it.\n\nThis just adds a guard to check that the name is not `NULL` before\ncopying from it. The server appears to have a similar pattern.","modified":"2026-10-07T14:16:57.671591970Z","published":"2026-10-06T09:18:29Z","upstream":["CVE-2026-98355"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-98355"}],"affected":[{"package":{"name":"kernel","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/kernel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"6.6.157.1-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-106209.json"}}],"schema_version":"1.9.0"}