{"id":"AZL-102948","summary":"CVE-2026-90056 affecting package kernel 6.6.150.1-1","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: fec: only stop PTP if it was initialized\n\nfec_ptp_init() is only called when fep-\u003ebufdesc_ex is available.\nHowever, fec_probe() unconditionally calls fec_ptp_stop() on the\nfailed_init path, and fec_drv_remove() unconditionally calls\nfec_ptp_stop() during device removal.\n\nCheck fep-\u003ebufdesc_ex before calling fec_ptp_stop() in both paths\nto avoid stopping PTP when it was not initialized.","modified":"2026-09-19T05:33:49Z","published":"2026-09-17T17:16:54Z","upstream":["CVE-2026-90056"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-90056"}],"affected":[{"package":{"name":"kernel","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/kernel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"6.6.150.1-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-102948.json"}}],"schema_version":"1.9.0"}