{"id":"AZL-102170","summary":"CVE-2026-90368 affecting package kernel 6.6.150.1-1","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mt76: mt7915: unwind state on add_interface failure\n\nWhen mt76_wcid_alloc() fails, mt7915_add_interface() returned without\nclearing the vif_mask/omac_mask bits it had already set, without removing\nthe firmware dev info added earlier, and without clearing a monitor_vif\npointer to the vif mac80211 is about to free. mac80211 does not call\nremove_interface() for a failed add, so the indices and firmware dev\nentry leaked permanently and testmode could dereference the stale\nmonitor_vif. Add a proper error unwind.","modified":"2026-09-18T14:16:32.075575234Z","published":"2026-09-17T17:17:35Z","upstream":["CVE-2026-90368"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-90368"}],"affected":[{"package":{"name":"kernel","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/kernel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"6.6.150.1-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-102170.json"}}],"schema_version":"1.9.0"}