{"id":"AZL-102915","summary":"CVE-2026-90274 affecting package kernel 6.6.150.1-1","details":"In the Linux kernel, the following vulnerability has been resolved:\n\ncoresight: etm4x: fix underflow for usage of (nrseqstate - 1)\n\nAccording to IHI006H Embedded Trace Macrocell Architecture\nSpecification[0], TRCSEQEVR\u003cn\u003e is implemented only when\nTRCIDR5.NUMSEQSTATE is 0b100, in which case n ranges from 0 to 2;\notherwise, TRCIDR5.NUMSEQSTATE is 0b000.\n\nIOW, the number of usage in the initialisation or setting\nTRCSEQEVR\u003cn\u003e with drvdata-\u003enrseqstate - 1 in the loop could make\nunderflow issue when TRCIDR5.NUMSEQSTATE is 0b000.\n\nTherefore, introduce nr_seq_ctrls field and untie it from nrseqstate.\nAs part of this introduce ETM_MAX_SEQ_TRANSITIONS macro and\napply nr_seq_ctrls and above macro to TRCSEQEVR\u003cn\u003e relevant fields setup.","modified":"2026-09-19T05:33:49Z","published":"2026-09-17T17:17:23Z","upstream":["CVE-2026-90274"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-90274"}],"affected":[{"package":{"name":"kernel","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/kernel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"6.6.150.1-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-102915.json"}}],"schema_version":"1.9.0"}