{"id":"AZL-102267","summary":"CVE-2026-90330 affecting package kernel 6.6.150.1-1","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nHID: logitech-hidpp: Fix FF device cleanup on init failure\n\nhidpp_ff_init() creates the input force-feedback device with\ninput_ff_create(), then allocates the HID++ FF private data,\neffect ID array, and workqueue.\n\nIf any of those allocations fail after input_ff_create() succeeds,\nthe function returns an error without destroying the FF device.\nAdd an unwind path that frees the private allocations made by\nhidpp_ff_init() and calls input_ff_destroy() for failures after\ninput_ff_create() succeeds.","modified":"2026-09-18T14:17:50.143821458Z","published":"2026-09-17T17:17:31Z","upstream":["CVE-2026-90330"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-90330"}],"affected":[{"package":{"name":"kernel","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/kernel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"6.6.150.1-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-102267.json"}}],"schema_version":"1.9.0"}