{"id":"AZL-101945","summary":"CVE-2026-92504 affecting package kernel 6.6.150.1-1","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nthermal: intel: int3400: clean up ODVP on probe failures\n\nevaluate_odvp() creates per-ODVP sysfs files before the thermal zone\nand later probe resources are registered. The current unwind path only\ncalls cleanup_odvp() from the late sysfs failure path, so failures after\nevaluate_odvp() but before that label, including\nthermal_tripless_zone_device_register() failures, leave the ODVP files\nand storage behind.\n\nMove the ODVP cleanup to the common ART/TRT unwind path so every failure\nafter evaluate_odvp() releases the ODVP state. Also clear the cached\nODVP pointers in cleanup_odvp(), because evaluate_odvp() can already call\nit for partial setup failures while probe continues.","modified":"2026-09-18T14:15:26.148672145Z","published":"2026-09-17T17:17:52Z","upstream":["CVE-2026-92504"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-92504"}],"affected":[{"package":{"name":"kernel","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/kernel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"6.6.150.1-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-101945.json"}}],"schema_version":"1.9.0"}