PT-2026-98669 · Linux · Linux

CVE-2026-98006

·

Published

2026-09-25

·

Updated

2026-09-25

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
ALSA: caiaq: Decoupling ep1 in urb in caiaq dev
The epq in urb object belonging to the caiaq device is coupled within the struct snd usb caiaqdev. After usb submit urb(epq in urb, GFP KERNEL) executes successfully, epq in urb is successfully added to the urbp list queue of the dummy HCD driver (userspace specifies dummy hcd as the HCD layer driver for the caiaq USB device).
When init card() calls snd usb caiaq send command() which subsequently fails due to a timeout, and proceeds to call snd card free() to release the card, the embedded ep1 in urb object is also freed. When the dummy HCD driver detects that the URB has been unlinked, it returns the URB (by usb hcd giveback urb()), which triggers [1].
Decouple the ep1 in urb object from the struct snd usb caiaqdev and switch to using a pointer instead. Separately allocate and manage the memory for ep1 in urb to prevent the release of the snd card memory object from interfering with it.
midi out urb has the same issue as ep1 in urb and is handled in the same way.
[1] BUG: KASAN: slab-use-after-free in usb free urb+0x24/0x120 drivers/usb/core/urb.c:96 Write of size 4 at addr ffff88803cee1050 by task ktimers/1/29 Call Trace: usb free urb+0x24/0x120 drivers/usb/core/urb.c:96 dummy timer+0xaac/0x4d50 drivers/usb/gadget/udc/dummy hcd.c:2019 run hrtimer kernel/time/hrtimer.c:2067 [inline] hrtimer run queues+0x3eb/0xaf0 kernel/time/hrtimer.c:2124 hrtimer run softirq+0x1e1/0x2e0 kernel/time/hrtimer.c:2141
Allocated by task 36: snd card new+0x7b/0x110 sound/core/init.c:184 create card sound/usb/caiaq/device.c:429 [inline] snd probe+0x236/0x1af0 sound/usb/caiaq/device.c:544
Freed by task 36: snd card free when closed sound/core/init.c:630 [inline] snd card free+0x138/0x1d0 sound/core/init.c:662 snd probe+0x162b/0x1af0 sound/usb/caiaq/device.c:553
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-98006

Affected Products

Linux