{"id":"AZL-104367","summary":"CVE-2026-98090 affecting package kernel 6.6.157.1-1","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: restore active device pointers after failed sprout\n\nbtrfs_init_new_device() switches latest_dev and possibly s_bdev from the\nseed device to the new sprout device before creating the first writable\nchunks.\n\nIf chunk creation or the subsequent sprout setup fails, the error path\nreleases the new device without switching those pointers back.\nbtrfs_show_devname() can then dereference the freed latest_dev and crash.\n\nRestore the active device pointers to the latest seed device before\nremoving and releasing the failed sprout device.","modified":"2026-09-27T05:34:32Z","published":"2026-09-25T11:17:38Z","upstream":["CVE-2026-98090"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-98090"}],"affected":[{"package":{"name":"kernel","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/kernel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"6.6.157.1-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-104367.json"}}],"schema_version":"1.9.0"}