{"id":"AZL-102156","summary":"CVE-2026-90336 affecting package kernel 6.6.150.1-1","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nserial: core: clear freed pointers on uart_register_driver() failure\n\nuart_register_driver() leaves drv-\u003estate pointing to freed memory when\ntty_alloc_driver() fails. If tty_register_driver() fails, drv-\u003etty_driver\nalso retains a pointer after its reference is dropped.\n\nDrivers that use drv-\u003estate as an \"already registered\" flag can then skip\nregistration on the next probe and pass the freed state to\nuart_add_one_port().\n\nThis issue was found with failslab on QEMU's raspi1ap board by\nfailing registration and binding the PL011 port again.\n\nClear both pointers on their failure paths, as uart_unregister_driver()\nalready does.","modified":"2026-09-18T14:17:49.386809542Z","published":"2026-09-17T17:17:32Z","upstream":["CVE-2026-90336"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-90336"}],"affected":[{"package":{"name":"kernel","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/kernel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"6.6.150.1-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-102156.json"}}],"schema_version":"1.9.0"}