{"id":"AZL-102260","summary":"CVE-2026-93090 affecting package kernel 6.6.150.1-1","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nfirmware: arm_scmi: Clean up channels on setup failure\n\nscmi_channels_setup() can fail after the common BASE channel or earlier\nprotocol channels have already been registered in the TX/RX IDRs.\n\nRoute this failure through the existing channel cleanup label so the\ntransport channels, transport devices and IDR state created before the\nfailure are released before the probe error path frees the SCMI instance\nID.","modified":"2026-09-18T14:17:49.654341562Z","published":"2026-09-17T17:18:02Z","upstream":["CVE-2026-93090"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-93090"}],"affected":[{"package":{"name":"kernel","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/kernel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"6.6.150.1-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-102260.json"}}],"schema_version":"1.9.0"}