{"id":"AZL-106350","summary":"CVE-2026-98251 affecting package kernel 6.6.157.1-1","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nopenvswitch: avoid reallocating confirmed conntrack labels\n\novs_ct_get_conn_labels() adds the labels extension when a conntrack\nentry does not have one.  Confirmed conntracks can be read locklessly,\nso adding an extension may reallocate and free the extension block\nwhile another CPU accesses it.\n\nOnly add the extension for unconfirmed conntracks.  A confirmed\nconntrack without labels now fails the caller's label operation instead\nof reallocating its extension storage.","modified":"2026-10-07T14:17:02.882167854Z","published":"2026-10-06T09:18:13Z","upstream":["CVE-2026-98251"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-98251"}],"affected":[{"package":{"name":"kernel","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/kernel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"6.6.157.1-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-106350.json"}}],"schema_version":"1.9.0"}