CVE-2026-98264
In the Linux kernel, the following vulnerability has been resolved:
ALSA: virtio: reset device before deleting virtqueues
virtsnd_remove() and virtsnd_freeze() delete the virtqueues before resetting the device. del_vqs() frees the vring backing, but does not provide a generic device quiesce operation. In particular, modern virtio-pci keeps enabled queues active until the device is reset.
Reset the device before deleting the virtqueues so it can no longer access the vring memory when that memory is released. This also covers probe failures after DRIVER_OK, which unwind through virtsnd_remove().
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.21%
- Percentil entre todas las CVEs puntuadas: 11
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/3e24b4a6acfd3bedb2200334595facd767c9a897
- https://git.kernel.org/stable/c/500a8401415ab085555785c3c339747e378abd36
- https://git.kernel.org/stable/c/6c05d00af307560e6a9f1631d6270d3df5aa2272
- https://git.kernel.org/stable/c/830012feadc228a938514a6487862dcf56af7e66
- https://git.kernel.org/stable/c/8edc3669e3e22f0123a1114c3a03df9abc4cd465
- https://git.kernel.org/stable/c/f070cce7cb361d5389b18f3ff6bd3d25a7596369
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-98264",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "de3a9980d8c34b2479173e809afa820473db676a",
"lessThan": "8edc3669e3e22f0123a1114c3a03df9abc4cd465",
"versionType": "git"
},
{
"status": "affected",
"version": "de3a9980d8c34b2479173e809afa820473db676a",
"lessThan": "830012feadc228a938514a6487862dcf56af7e66",
"versionType": "git"
},
{
"status": "affected",
"version": "de3a9980d8c34b2479173e809afa820473db676a",
"lessThan": "500a8401415ab085555785c3c339747e378abd36",
"versionType": "git"
},
{
"status": "affected",
"version": "de3a9980d8c34b2479173e809afa820473db676a",
"lessThan": "3e24b4a6acfd3bedb2200334595facd767c9a897",
"versionType": "git"
},
{
"status": "affected",
"version": "de3a9980d8c34b2479173e809afa820473db676a",
"lessThan": "f070cce7cb361d5389b18f3ff6bd3d25a7596369",
"versionType": "git"
},
{
"status": "affected",
"version": "de3a9980d8c34b2479173e809afa820473db676a",
"lessThan": "6c05d00af307560e6a9f1631d6270d3df5aa2272",
"versionType": "git"
}
],
"programFiles": [
"sound/virtio/virtio_card.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "5.13"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "5.13",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.1.189",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.158",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.112",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.54",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.2.8",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc4",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"sound/virtio/virtio_card.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-10-06T09:18:15.650",
"references": [
{
"url": "https://git.kernel.org/stable/c/3e24b4a6acfd3bedb2200334595facd767c9a897",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/500a8401415ab085555785c3c339747e378abd36",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/6c05d00af307560e6a9f1631d6270d3df5aa2272",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/830012feadc228a938514a6487862dcf56af7e66",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/8edc3669e3e22f0123a1114c3a03df9abc4cd465",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/f070cce7cb361d5389b18f3ff6bd3d25a7596369",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: virtio: reset device before deleting virtqueues\n\nvirtsnd_remove() and virtsnd_freeze() delete the virtqueues before\nresetting the device. del_vqs() frees the vring backing, but does not\nprovide a generic device quiesce operation. In particular, modern\nvirtio-pci keeps enabled queues active until the device is reset.\n\nReset the device before deleting the virtqueues so it can no longer\naccess the vring memory when that memory is released. This also covers\nprobe failures after DRIVER_OK, which unwind through virtsnd_remove()."
}
],
"lastModified": "2026-10-06T09:18:15.650",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}