{"id":"AZL-102623","summary":"CVE-2026-90219 affecting package kernel 6.6.150.1-1","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/cxgb4: Free debugfs on registration failure\n\nc4iw_alloc() creates the per-device debugfs tree (dev-\u003edebugfs_root via\nsetup_debugfs()), but it is removed only in c4iw_remove(), not in\nc4iw_dealloc().  When RDMA device registration fails, the registration\nworker's err_dealloc_ctx path calls c4iw_dealloc() directly, bypassing\nc4iw_remove(), so the debugfs dentries leak and outlive the freed\nc4iw_dev.\n\nMove debugfs_remove_recursive() into c4iw_dealloc() so every path that\nfrees ctx-\u003edev also removes its debugfs tree.","modified":"2026-09-18T14:18:02.845867618Z","published":"2026-09-17T17:17:17Z","upstream":["CVE-2026-90219"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-90219"}],"affected":[{"package":{"name":"kernel","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/kernel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"6.6.150.1-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-102623.json"}}],"schema_version":"1.9.0"}