-

CVE-2026-90198

ALSA: core: Fix use-after-free in snd_card_do_free()

In the Linux kernel, the following vulnerability has been resolved:

ALSA: core: Fix use-after-free in snd_card_do_free()

A use-after-free was detected in snd_card_do_free() when a sound card
managed by devres is unbound while a user-space application still holds an
open file descriptor.

For managed cards, the memory is allocated using devres_alloc(), and its
release function is set to __snd_card_release(), which calls
snd_card_free(). When the device is unbound, the unbind thread calls
snd_card_free(), which drops a reference to the card's device. If the user
thread still has an open file descriptor, the reference count does not
reach zero, and the unbind thread blocks on wait_for_completion(&released).

When the user thread closes the file descriptor, it drops the final
reference, invoking the device release callback release_card_device(),
which calls snd_card_do_free(). snd_card_do_free() performs cleanup and
calls complete(card->release_completion). This wakes up the unbind thread,
which returns from snd_card_free() and __snd_card_release(). The devres
core then immediately frees the memory block containing the snd_card
structure.

Meanwhile, the user thread continues execution in snd_card_do_free() and
evaluates `if (!card->managed)`. It reads the `managed` boolean from the
snd_card structure that was just freed by the unbind thread, triggering a
KASAN use-after-free.

Fix this by caching the value of card->managed in a local variable before
calling complete(). This ensures that the card pointer is not dereferenced
after the unbind thread has been woken up and potentially freed the card.

BUG: KASAN: use-after-free in snd_card_do_free sound/core/init.c:604
[inline]
BUG: KASAN: use-after-free in release_card_device+0x1ab/0x1b0
sound/core/init.c:153
Read of size 1 at addr ffff8881912ec909 by task syz-executor130/5857

Call Trace:
 <TASK>
 dump_stack_lvl+0xe8/0x150 lib/dump_stack.c:120
 print_address_description+0x55/0x1e0 mm/kasan/report.c:378
 print_report+0x58/0x70 mm/kasan/report.c:482
 kasan_report+0x117/0x150 mm/kasan/report.c:595
 snd_card_do_free sound/core/init.c:604 [inline]
 release_card_device+0x1ab/0x1b0 sound/core/init.c:153
 device_release+0xc4/0x1f0 drivers/base/core.c:-1
 kobject_cleanup lib/kobject.c:689 [inline]
 kobject_release lib/kobject.c:720 [inline]
 kref_put include/linux/kref.h:65 [inline]
 kobject_put+0x222/0x550 lib/kobject.c:737
 snd_card_file_remove+0x331/0x390 sound/core/init.c:1125
 snd_pcm_release+0x12c/0x160 sound/core/pcm_native.c:2986
 __fput+0x418/0xa50 fs/file_table.c:512
 fput_close_sync+0x11f/0x240 fs/file_table.c:617
 __do_sys_close fs/open.c:1511 [inline]
 __se_sys_close fs/open.c:1496 [inline]
 __x64_sys_close+0x7e/0x110 fs/open.c:1496
 do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
 do_syscall_64+0x174/0x580 arch/x86/entry/syscall_64.c:94
 entry_SYSCALL_64_after_hwframe+0x77/0x7f
 </TASK>
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version e8ad415b7a55cb9a9fbfc04696518d5ea0b609b3
Version < d3d67f680dbc23a5e5e3d3ecfdbf700465809877
Status affected
Version e8ad415b7a55cb9a9fbfc04696518d5ea0b609b3
Version < 09b27dd01b98480334c10bf6fb8d41d5fb063a4b
Status affected
Version e8ad415b7a55cb9a9fbfc04696518d5ea0b609b3
Version < 03c5dabc8f16bc212a5b26d2425c03a55e55a86d
Status affected
Version e8ad415b7a55cb9a9fbfc04696518d5ea0b609b3
Version < 6da22efb5cf490b06ffbca32b10fc8af7654fee0
Status affected
Version e8ad415b7a55cb9a9fbfc04696518d5ea0b609b3
Version < a561012868ae37c28f61fdf658bf6f251bc0e8e8
Status affected
Version e8ad415b7a55cb9a9fbfc04696518d5ea0b609b3
Version < 7d9b5e86775fa97a487da08b9aa76e1674bf8868
Status affected
Version e8ad415b7a55cb9a9fbfc04696518d5ea0b609b3
Version < 5ae1a690c522fea2900ff56c8c2ace7b059f5e04
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 5.15
Status affected
Version 0
Version < 5.15
Status unaffected
Version <= 5.15.*
Version 5.15.221
Status unaffected
Version <= 6.1.*
Version 6.1.188
Status unaffected
Version <= 6.6.*
Version 6.6.157
Status unaffected
Version <= 6.12.*
Version 6.12.110
Status unaffected
Version <= 6.18.*
Version 6.18.52
Status unaffected
Version <= 7.2.*
Version 7.2.6
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.22% 0.13
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/d3d67f680dbc23a5e5e3d3ecfdbf700465809877
https://git.kernel.org/stable/c/09b27dd01b98480334c10bf6fb8d41d5fb063a4b
https://git.kernel.org/stable/c/03c5dabc8f16bc212a5b26d2425c03a55e55a86d
https://git.kernel.org/stable/c/6da22efb5cf490b06ffbca32b10fc8af7654fee0
https://git.kernel.org/stable/c/a561012868ae37c28f61fdf658bf6f251bc0e8e8
https://git.kernel.org/stable/c/7d9b5e86775fa97a487da08b9aa76e1674bf8868
https://git.kernel.org/stable/c/5ae1a690c522fea2900ff56c8c2ace7b059f5e04