PT-2026-106595 · Linux · Linux

CVE-2026-98266

·

Published

2026-10-06

·

Updated

2026-10-06

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
ALSA: core: Fix potential UAF after asynchronous card release
Usually a sound driver releases the resources assigned to the card via snd card free(), and it synchronizes with the whole release procedure. However, when the card is released asynchronously via snd card free when closed() like USB-audio driver, the situation is slightly different; although the snd card disconnect() call at the disconnection guarantees that any newer accesses will be gated, the in-flight tasks might be still accessing to the underlying card->dev device even after the disconnection, which would cause a use-after-free in the end, as reported by fuzzers.
For addressing the bug above, this patch takes the refcount of card->dev at initialization of the card object, and releases at its destructor. This assures the availability of the card->dev in its whole lifecycle.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-98266

Affected Products

Linux