Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-92582.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-92582
Upstream
Published
2026-07-19T15:16:52Z
Modified
2026-08-30T05:26:50Z
Summary
CVE-2026-63858 affecting package kernel 6.6.150.1-1
Details

In the Linux kernel, the following vulnerability has been resolved:

netfilter: nf_tables: add hook transactions for device deletions

Restore the flag that indicates that the hook is going away, ie. NFTHOOKREMOVE, but add a new transaction object to track deletion of hooks without altering the basechain/flowtable hook_list during the preparation phase.

The existing approach that moves the hook from the basechain/flowtable hooklist to transaction hooklist breaks netlink dump path readers of this RCU-protected list.

It should be possible use an array for nfttranshook to store the deleted hooks to compact the representation but I am not expecting many hook object, specially now that wildcard support for devices is in place.

Note that the nfttranschainhooks() list contains a list of struct nfttranshook objects for DELCHAIN and DELFLOWTABLE commands, while this list stores struct nfthook objects for NEWCHAIN and NEWFLOWTABLE. Note that new commands can be updated to use nfttranshook for consistency.

This patch also adapts the event notification path to deal with the list of hook transactions.

References

Affected packages

Azure Linux:3 / kernel

Package

Name
kernel
Purl
pkg:rpm/azure-linux/kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
6.6.150.1-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-92582.json"