{"id":"AZL-103790","summary":"CVE-2026-97473 affecting package kernel 6.6.157.1-1","details":"In the Linux kernel, the following vulnerability has been resolved:\n\npowercap: intel_rapl: Fix memory leak in rapl_add_package_cpuslocked()\n\nWhen topology_physical_package_id()/topology_logical_die_id() returns\na negative value, rapl_add_package_cpuslocked() returns ERR_PTR(-EINVAL)\ndirectly without freeing the rapl_package structure that was just\nallocated by kzalloc_obj(), leaking memory on every failed package\naddition.\n\nUse the existing err_free_package label so that the allocation is\nreleased on the error path.","modified":"2026-09-25T14:15:47.471420643Z","published":"2026-09-24T17:17:24Z","upstream":["CVE-2026-97473"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-97473"}],"affected":[{"package":{"name":"kernel","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/kernel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"6.6.157.1-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-103790.json"}}],"schema_version":"1.9.0"}