« Volver al listado

CVE-2026-89944

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

ASoC: hdac_hda: Fix hlink refcount leak on component registration failure

hdac_hda_dev_probe() gets the HDA link with snd_hdac_ext_bus_link_get() before registering the ASoC component. If component registration fails, the function returns without dropping the link reference.

Always call snd_hdac_ext_bus_link_put() after the registration attempt so the reference taken during probe is balanced on both success and failure.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-89944",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6bae5ea9498926440ffc883f3dbceb0adc65e492",
              "lessThan": "7eef9ae3b4ef782557526dd8ba0c206f028d8c2f",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "6bae5ea9498926440ffc883f3dbceb0adc65e492",
              "lessThan": "e8ea01a0457080b0cc7c69c430c0ab65d84dc377",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "6bae5ea9498926440ffc883f3dbceb0adc65e492",
              "lessThan": "cb6b0b1a9d5a61ef841739d42c6211094e9c8e2c",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "6bae5ea9498926440ffc883f3dbceb0adc65e492",
              "lessThan": "6ad4892c4f5cb437a928a02f5b7d37d496aa9268",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "sound/soc/codecs/hdac_hda.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "4.20"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "4.20",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.12.110",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.51",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.5",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "sound/soc/codecs/hdac_hda.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-16T11:17:04.217",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/6ad4892c4f5cb437a928a02f5b7d37d496aa9268",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/7eef9ae3b4ef782557526dd8ba0c206f028d8c2f",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/cb6b0b1a9d5a61ef841739d42c6211094e9c8e2c",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/e8ea01a0457080b0cc7c69c430c0ab65d84dc377",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: hdac_hda: Fix hlink refcount leak on component registration failure\n\nhdac_hda_dev_probe() gets the HDA link with snd_hdac_ext_bus_link_get()\nbefore registering the ASoC component. If component registration fails,\nthe function returns without dropping the link reference.\n\nAlways call snd_hdac_ext_bus_link_put() after the registration attempt so\nthe reference taken during probe is balanced on both success and failure."
    }
  ],
  "lastModified": "2026-09-16T11:17:04.217",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}