PT-2026-93673 · Linux · Linux Kernel

CVE-2026-90032

·

Published

2026-09-16

·

Updated

2026-09-24

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the usbtv media component where an open PCM file can remain active after a USB disconnect. This occurs because usbtv audio free() utilizes snd card free when closed(), allowing the disconnect process to drop the V4L2 device reference and free the usbtv structure before ALSA releases the substream. Consequently, a subsequent close operation leads to a use-after-free condition in the snd usbtv pcm close() function, where freed memory is dereferenced.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-101586
CVE-2026-90032
OPENSUSE-SU-2026:11880-1

Affected Products

Linux Kernel