« Volver al listado

CVE-2026-98266

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

ALSA: core: Fix potential UAF after asynchronous card release

Usually a sound driver releases the resources assigned to the card via snd_card_free(), and it synchronizes with the whole release procedure. However, when the card is released asynchronously via snd_card_free_when_closed() like USB-audio driver, the situation is slightly different; although the snd_card_disconnect() call at the disconnection guarantees that any newer accesses will be gated, the in-flight tasks might be still accessing to the underlying card->dev device even after the disconnection, which would cause a use-after-free in the end, as reported by fuzzers.

Leer descripción completaMostrar menos

For addressing the bug above, this patch takes the refcount of card->dev at initialization of the card object, and releases at its destructor. This assures the availability of the card->dev in its whole lifecycle.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-98266",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
              "lessThan": "5c0df40aa577e405c458e44e8d458dd78407f4af",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
              "lessThan": "2dec4642589a663e064e4411d92d6e8fa250d53b",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
              "lessThan": "398b21608955c9712a012355b69a39407367edc9",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
              "lessThan": "fd95e68df6fe66344161a1329cbe5e5805e7b704",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "0",
              "lessThan": "6.12.112",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "0",
              "lessThan": "6.18.54",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "0",
              "lessThan": "7.2.8",
              "versionType": "semver"
            }
          ],
          "programFiles": [
            "sound/core/init.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "unaffected",
              "version": "6.12.112",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.54",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.8",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc4",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "sound/core/init.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-10-06T09:18:15.960",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/2dec4642589a663e064e4411d92d6e8fa250d53b",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/398b21608955c9712a012355b69a39407367edc9",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/5c0df40aa577e405c458e44e8d458dd78407f4af",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/fd95e68df6fe66344161a1329cbe5e5805e7b704",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: core: Fix potential UAF after asynchronous card release\n\nUsually a sound driver releases the resources assigned to the card via\nsnd_card_free(), and it synchronizes with the whole release procedure.\nHowever, when the card is released asynchronously via\nsnd_card_free_when_closed() like USB-audio driver, the situation is\nslightly different; although the snd_card_disconnect() call at the\ndisconnection guarantees that any newer accesses will be gated, the\nin-flight tasks might be still accessing to the underlying card->dev\ndevice even after the disconnection, which would cause a\nuse-after-free in the end, as reported by fuzzers.\n\nFor addressing the bug above, this patch takes the refcount of\ncard->dev at initialization of the card object, and releases at its\ndestructor.   This assures the availability of the card->dev in its\nwhole lifecycle."
    }
  ],
  "lastModified": "2026-10-06T09:18:15.960",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}