AZL-105729

See a problem?
Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-105729.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-105729
Upstream
  • CVE-2026-15390
Published
2026-09-29T10:17:11Z
Modified
2026-10-05T05:34:30Z
Summary
CVE-2026-15390 affecting package qemu 10.1.0-1
Details

Das U-Boot with CONFIG_IP_DEFRAG=y parameter fails to clear IP reassembly state after delivering a complete datagram. An attacker who can deliver fragmented IP traffic can execute arbitrary code by sending duplicated last-fragment IP packets.

This issue was fixed in commit b1aec609bb5e0d08c25c888c91935287ab4ee5fa in version 2026.07.

References

Affected packages

Azure Linux:3 / qemu

Package

Name
qemu
Purl
pkg:rpm/azure-linux/qemu

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
10.1.0-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-105729.json"