{"id":"AZL-102984","summary":"CVE-2026-90364 affecting package kernel 6.6.150.1-1","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nACPI: processor: Unregister cpufreq notifier on init failure\n\nacpi_processor_driver_init() registers the cpufreq policy notifier before\nregistering the ACPI processor driver and setting up CPU hotplug state.\n\nIf driver_register() or cpuhp_setup_state() fails, the error path only\nunregisters the ACPI processor driver and the idle driver. The cpufreq\nnotifier remains registered even though initialization failed.\n\nMirror the module exit path on the init failure path and unregister the\ncpufreq notifier when it has been registered.","modified":"2026-09-18T14:18:02.998792778Z","published":"2026-09-17T17:17:35Z","upstream":["CVE-2026-90364"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-90364"}],"affected":[{"package":{"name":"kernel","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/kernel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"6.6.150.1-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-102984.json"}}],"schema_version":"1.9.0"}