{"id":"AZL-102597","summary":"CVE-2026-92490 affecting package kernel 6.6.150.1-1","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nfirmware: arm_scmi: Unrequest devices if driver registration fails\n\nscmi_driver_register() requests protocol devices before registering the\ndriver. If driver_register() fails, those requests remain in the global\nIDR and retain pointers to the module's ID table. Once the failed module\nload releases that storage, later request matching or SCMI device creation\ncan dereference the stale pointers.\n\nUnrequest the complete protocol table before returning the registration\nfailure. At this point table registration succeeded, so every entry is\nowned by the current registration attempt.","modified":"2026-09-19T05:33:49Z","published":"2026-09-17T17:17:51Z","upstream":["CVE-2026-92490"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-92490"}],"affected":[{"package":{"name":"kernel","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/kernel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"6.6.150.1-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-102597.json"}}],"schema_version":"1.9.0"}