CYBER CODE RED

Get real-time updates on Telegram

P4Verified

CVE-2026-90030: Linux 6.9

CVE-2026-90030 affects azl3 kernel 6.6.157.1-1 on Azure Linux 3.0. CVSS 3.1 base score 7.8 (HIGH, Microsoft Security Response Center). EPSS 0.00175 (percentile 0.06368), scored 06-Oct-2026. Fixed version: 7.2.6-1. Fixed version: 6.12.112-r0. Fixed version: 6.18.53-r0.

Affected technology

Linux · 1e43c86d84fb0503e82a143e017f35421498fc1a to before 9f1e57c484f9edeaaa5a27a03ed985e98496e81d, 1e43c86d84fb0503e82a143e017f35421498fc1a to before 0afe5c31612de3d18cc6d16e616da4a48ba1e5a2, 1e43c86d84fb0503e82a143e017f35421498fc1a to before e01408ee52fe5cb2d0b43f47f359336af2b6c316, 1e43c86d84fb0503e82a143e017f35421498fc1a to before b58e6200450d350314db0ecda7d6d1bde3281e80, ab99c4be945724b032cc55e05c6738fe1d84bf70, 6.6.37 to before 6.7
Linux

Linux · 6.9
Linux

Component: Not specified by the source
File: drivers/usb/dwc3/ep0.c, drivers/usb/dwc3/gadget.c

Attack conditions (Source advisory, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

Source advisory’s CVSS 3.1 assessment (base score 7.8/10) rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

Published

Product
azl3 kernel 6.6.157.1-1 on Azure Linux 3.0
CCR priority
31.2 /100 (P4)
CVSS 3.1
7.8 /10 · CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U · Microsoft Security Response Center
EPSS
0.00175 · percentile 0.06429 · 2026-10-10
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2026-90030.html