PT-2026-93673 · Linux · Linux Kernel
CVE-2026-90032
·
Published
2026-09-16
·
Updated
2026-09-24
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
An issue exists in the
usbtv media component where an open PCM file can remain active after a USB disconnect. This occurs because usbtv audio free() utilizes snd card free when closed(), allowing the disconnect process to drop the V4L2 device reference and free the usbtv structure before ALSA releases the substream. Consequently, a subsequent close operation leads to a use-after-free condition in the snd usbtv pcm close() function, where freed memory is dereferenced.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel