{"id":"AZL-102297","summary":"CVE-2026-93102 affecting package kernel 6.6.150.1-1","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/hfi1: Free RX data on late probe failure\n\nhfi1_init_dd() allocates the shared AIP/VNIC RX support before returning.\nIf hfi1_init() or hfi1_register_ib_device() later fails, init_one() tears\ndown the device data without calling hfi1_free_rx(). This leaks netdev_rx\nand its dummy netdev.\n\nFree the RX support after IB unregistration and before postinit_cleanup(),\nas done on normal device removal.","modified":"2026-09-18T14:17:50.043629561Z","published":"2026-09-17T17:18:04Z","upstream":["CVE-2026-93102"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-93102"}],"affected":[{"package":{"name":"kernel","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/kernel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"6.6.150.1-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-102297.json"}}],"schema_version":"1.9.0"}