Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-97691.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-97691
Upstream
Published
2026-08-26T15:17:14Z
Modified
2026-08-30T05:26:50Z
Summary
CVE-2026-80584 affecting package kernel 6.6.150.1-1
Details

In the Linux kernel, the following vulnerability has been resolved:

s390/qeth: validate user buffer length in SNMP and ARP query ioctls

qethsnmpcommand() and qethl3arpquery() allocate a buffer sized by a user-supplied length (udatalen) without checking a lower bound, then set udata_offset to a fixed non-zero value and pass both to a reply callback. The callback bounds-checks the copy with

    if ((udata_len - udata_offset) < len)

Both fields are u32, so a udatalen smaller than udataoffset makes the subtraction wrap and the check pass, and the following memcpy() writes past the allocation. A udatalen of 0 also yields ZEROSIZE_PTR from kzalloc(), which the existing NULL check does not catch.

Reject buffers smaller than udata_offset before allocating, so the callback subtraction can no longer underflow.

References

Affected packages

Azure Linux:3 / kernel

Package

Name
kernel
Purl
pkg:rpm/azure-linux/kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
6.6.150.1-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-97691.json"