{"id":"AZL-101981","summary":"CVE-2026-90353 affecting package kernel 6.6.150.1-1","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mt76: mt7915: fix ext PHY use-after-free on register error path\n\nAfter mt7915_register_ext_phy() succeeded, a failure of the main PHY\nmt7915_init_debugfs() or mt7915_coredump_register() unwound through\nfree_phy2, which called ieee80211_free_hw() on the ext PHY hw while it\nwas still registered with mac80211, since mt76_unregister_device() only\nunregisters the main hw. Unregister the ext PHY (thermal + phy + hw)\nfirst and skip the redundant free.","modified":"2026-09-18T14:15:26.147362940Z","published":"2026-09-17T17:17:34Z","upstream":["CVE-2026-90353"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-90353"}],"affected":[{"package":{"name":"kernel","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/kernel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"6.6.150.1-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-101981.json"}}],"schema_version":"1.9.0"}