{"id":"AZL-106233","summary":"CVE-2026-98204 affecting package kernel 6.6.157.1-1","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nInput: rmi_smbus - fix out-of-bounds read in rmi_smb_write_block()\n\nWhen chunking writes into SMBus blocks in rmi_smb_write_block(), the\nloop calculates block_len using the original total length (len) instead\nof the remaining length (cur_len).\n\nIf len is greater than 32 bytes (SMB_MAX_COUNT), block_len remains 32\nfor every iteration, even on the final partial chunk where fewer than 32\nbytes remain. This causes smb_block_write() to read 32 bytes from the\nadvanced data buffer pointer, reading past the end of the input buffer.\n\nFix this by calculating block_len using cur_len and advancing the buffer\nand address pointers by block_len.","modified":"2026-10-07T14:17:00.640946510Z","published":"2026-10-06T09:18:06Z","upstream":["CVE-2026-98204"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-98204"}],"affected":[{"package":{"name":"kernel","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/kernel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"6.6.157.1-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-106233.json"}}],"schema_version":"1.9.0"}