{"id":"AZL-101858","summary":"CVE-2026-90392 affecting package kernel 6.6.150.1-1","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Fix potential UAF when reading bpf link info\n\nIn bpf_link_show_fdinfo and bpf_link_get_info_by_fd, link-\u003eprog is\naccessed without holding any locks. If the prog is concurrently replaced\nvia bpf_link_update, the old prog can be freed, leading to a potential\nUAF issue.\n\nFix this by accessing link-\u003eprog under RCU protection to safely fetch\nthe pointer and guarantee its lifetime while reading its fields.","modified":"2026-09-18T14:16:29.121623308Z","published":"2026-09-17T17:17:38Z","upstream":["CVE-2026-90392"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-90392"}],"affected":[{"package":{"name":"kernel","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/kernel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"6.6.150.1-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-101858.json"}}],"schema_version":"1.9.0"}