-

CVE-2026-98266

ALSA: core: Fix potential UAF after asynchronous card release

In the Linux kernel, the following vulnerability has been resolved:

ALSA: core: Fix potential UAF after asynchronous card release

Usually a sound driver releases the resources assigned to the card via
snd_card_free(), and it synchronizes with the whole release procedure.
However, when the card is released asynchronously via
snd_card_free_when_closed() like USB-audio driver, the situation is
slightly different; although the snd_card_disconnect() call at the
disconnection guarantees that any newer accesses will be gated, the
in-flight tasks might be still accessing to the underlying card->dev
device even after the disconnection, which would cause a
use-after-free in the end, as reported by fuzzers.

For addressing the bug above, this patch takes the refcount of
card->dev at initialization of the card object, and releases at its
destructor.   This assures the availability of the card->dev in its
whole lifecycle.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < 5c0df40aa577e405c458e44e8d458dd78407f4af
Status affected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < 2dec4642589a663e064e4411d92d6e8fa250d53b
Status affected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < 398b21608955c9712a012355b69a39407367edc9
Status affected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < fd95e68df6fe66344161a1329cbe5e5805e7b704
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 2.6.12
Status affected
Version 0
Version < 2.6.12
Status unaffected
Version <= 6.12.*
Version 6.12.112
Status unaffected
Version <= 6.18.*
Version 6.18.54
Status unaffected
Version <= 7.2.*
Version 7.2.8
Status unaffected
Version <= *
Version 7.3-rc4
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.17% 0.055
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/5c0df40aa577e405c458e44e8d458dd78407f4af
https://git.kernel.org/stable/c/2dec4642589a663e064e4411d92d6e8fa250d53b
https://git.kernel.org/stable/c/398b21608955c9712a012355b69a39407367edc9
https://git.kernel.org/stable/c/fd95e68df6fe66344161a1329cbe5e5805e7b704