{"id":"AZL-102003","summary":"CVE-2026-90361 affecting package kernel 6.6.150.1-1","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ath11k: fix leak in ath11k_service_ready_ext_event()\n\nCurrently, during ath11k_service_ready_ext_event() processing,\nsvc_rdy_ext.mac_phy_caps can be allocated during TLV parsing. This is a\ntemporary allocation that is freed on the success path, but not on the\nerror path. If parsing succeeds far enough to allocate mac_phy_caps and\nthen fails on a later TLV, the allocation leaks. So free the allocation\non the error path.\n\nCompile tested only.","modified":"2026-09-18T14:15:25.786968330Z","published":"2026-09-17T17:17:35Z","upstream":["CVE-2026-90361"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-90361"}],"affected":[{"package":{"name":"kernel","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/kernel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"6.6.150.1-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-102003.json"}}],"schema_version":"1.9.0"}