Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-96288.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-96288
Upstream
Published
2026-08-15T06:22:35Z
Modified
2026-08-30T05:26:50Z
Summary
CVE-2026-74344 affecting package kernel 6.6.150.1-1
Details

In the Linux kernel, the following vulnerability has been resolved:

bpf: Clear rb node linkage when freeing bpfrbroot

bpfrbrootfree() detaches the root by copying the current rbrootcached and then replacing the live root with RBROOT_CACHED. It then walks the copied root and drops each object contained in the tree.

This leaves the rb node state intact while dropping the object. If the object is refcounted and survives the drop, its bpfrbnodekern still contains an owner pointer to the freed root and stale rb tree linkage. If a later bpfrbroot allocation reuses the same address, bpfrbtreeremove() can incorrectly pass the owner check and call rberase_cached() on a node whose rb pointers belong to the old tree.

Mirror the list draining behavior by marking nodes as busy while the root is being detached, then clear the rb node and release the owner before dropping the containing object. This makes surviving nodes unowned and safe to reject from remove or accept for a later add.

References

Affected packages

Azure Linux:3 / kernel

Package

Name
kernel
Purl
pkg:rpm/azure-linux/kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
6.6.150.1-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-96288.json"