PT-2026-94562 · Linux · Linux Kernel

CVE-2026-90214

·

Published

2026-09-17

·

Updated

2026-09-24

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the ASOC xilinx formatter pcm component where stream data is leaked during an open error. In the xlnx formatter pcm open() function, stream data is allocated and assigned to adata->play stream or adata->capture stream. If subsequent operations, such as snd pcm hw constraint step() or snd pcm hw constraint integer(), fail, the function returns an error without freeing the allocated memory. Because ALSA does not trigger the close callback upon an open failure, the stream pointer remains dangling, pointing to a substream that ALSA has already freed. This can lead to a situation where a subsequent interrupt calls snd pcm period elapsed() on the freed substream.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-102305
CVE-2026-90214
OPENSUSE-SU-2026:11880-1

Affected Products

Linux Kernel