{"id":"AZL-106458","summary":"CVE-2026-98323 affecting package kernel 6.6.157.1-1","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/siw: Bound fragmented header copies by the remaining length\n\nsiw_get_hdr() can receive an extended DDP/RDMAP header across more than\none TCP callback. The first callback may receive most of the header,\nwhile the next one still limits the copy to hdrlen - MIN_DDP_HDR instead\nof the number of missing bytes. This makes the destination move past the\nend of the header and overwrite the receive state, including\nfpdu_part_rcvd. A later callback can then use a negative fpdu_part_rcvd\nvalue as a copy offset, which creates an OOB write.\n\nUse the number of header bytes already received when calculating the\nnext copy length.","modified":"2026-10-07T14:17:06.720880352Z","published":"2026-10-06T09:18:24Z","upstream":["CVE-2026-98323"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-98323"}],"affected":[{"package":{"name":"kernel","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/kernel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"6.6.157.1-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-106458.json"}}],"schema_version":"1.9.0"}