{"id":"AZL-102612","summary":"CVE-2026-90318 affecting package kernel 6.6.150.1-1","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nfat: release buffer head after rebuilding parent\n\nfat_scan_logstart() leaves the matching directory entry's buffer head in\nsinfo.bh for the caller to release, just like fat_scan().\n\nfat_rebuild_parent() uses the directory entry to rebuild the parent inode\nfor the nostale_ro NFS export path, but does not release sinfo.bh after a\nsuccessful scan.  Release it once fat_build_inode() has consumed the\ndirectory entry data.","modified":"2026-09-18T14:18:02.743559327Z","published":"2026-09-17T17:17:29Z","upstream":["CVE-2026-90318"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-90318"}],"affected":[{"package":{"name":"kernel","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/kernel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"6.6.150.1-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-102612.json"}}],"schema_version":"1.9.0"}