{"id":"AZL-106290","summary":"CVE-2026-98354 affecting package kernel 6.6.157.1-1","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/mad: Fix receive buffer leak when PKey enforcement fails\n\nib_mad_complete_recv() initializes mad_recv_wc-\u003ermpp_list and then runs\nib_mad_enforce_security() before linking recv_buf onto that list.  On\nfailure it calls ib_free_recv_mad(), which only walks rmpp_list and frees\nthe ib_mad_private of every buffer found there.  As the list is still\nempty at that point, nothing is freed at all.\n\nThe caller cannot clean up either: ib_mad_recv_done() sets recv to NULL\nright after ib_mad_complete_recv() returns, assuming the MAD layer took\nownership of the buffer.  Every MAD that fails the PKey check therefore\nleaks one ib_mad_private (about 300 bytes per IB port MAD, ~2K for OPA),\nand a remote node can trigger this repeatedly by sending MADs with a\nwrong PKey.\n\nLink recv_buf onto rmpp_list right after the list is initialized, so the\nerror path has something to free.","modified":"2026-10-07T14:16:59.820967678Z","published":"2026-10-06T09:18:28Z","upstream":["CVE-2026-98354"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-98354"}],"affected":[{"package":{"name":"kernel","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/kernel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"6.6.157.1-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-106290.json"}}],"schema_version":"1.9.0"}