{"id":"AZL-102833","summary":"CVE-2026-90135 affecting package kernel 6.6.150.1-1","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: add missing ref_tracker_dir_exit() to alloc_netdev_mqs()\n\nsashiko is reporting that trying to read /sys/kernel/debug/ref_tracker/*\ncauses use-afer-free crash when either alloc_percpu() or dev_addr_init()\nin alloc_netdev_mqs() failed, for commit 4d92b95ff2f9 (\"net: add net device\nrefcount tracker infrastructure\") added ref_tracker_dir_exit() to only\nfree_netdev() path.","modified":"2026-09-19T05:33:49Z","published":"2026-09-17T17:17:06Z","upstream":["CVE-2026-90135"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-90135"}],"affected":[{"package":{"name":"kernel","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/kernel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"6.6.150.1-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-102833.json"}}],"schema_version":"1.9.0"}