{"id":"AZL-103047","summary":"CVE-2026-90161 affecting package kernel 6.6.150.1-1","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nerofs: fix interlaced ztailpacking pclusters\n\nOn-disk sizes of interlaced pclusters should be block-aligned, and\nztailpacking interlaced pclusters should be invalid at all.\n\nCurrently, mkfs.erofs won't generate any interlaced pcluster with\nztailpacking enabled, so this doesn't affect any existing valid\nfilesystems.\n\nHowever, crafted images can contain invalid interlaced ztailpacking\npclusters, resulting in an out-of-bounds read from a kmap'd page and\ncopying irrelevant kernel memory into userspace-visible page cache.","modified":"2026-09-18T14:18:03.201766938Z","published":"2026-09-17T17:17:09Z","upstream":["CVE-2026-90161"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-90161"}],"affected":[{"package":{"name":"kernel","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/kernel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"6.6.150.1-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-103047.json"}}],"schema_version":"1.9.0"}