๐Ÿ” CVE Alert

CVE-2026-89736

HIGH 7.8

usb: gadget: u_audio: Fix use-after-free on sound card disconnect

CVSS Score
7.8
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: u_audio: Fix use-after-free on sound card disconnect g_audio_cleanup() invokes snd_card_free_when_closed() to initiate sound card teardown and immediately frees the underlying struct snd_uac_chip context. However, snd_card_free_when_closed() returns asynchronously while ALSA control elements (kctls) remain open in userspace. When userspace control applications access or close these open file descriptors, kctl callbacks attempt to dereference kctl->private_data pointing to &uac->c_prm or &uac->p_prm within the freed uac structure, resulting in a use-after-free (UAF) memory corruption. Fix this issue by deferring the destruction of struct snd_uac_chip until all references to the ALSA sound card are released. Register a custom card->private_free callback (u_audio_card_free) during g_audio_setup() that frees uac and its associated playback/capture request and ring buffers only when the sound card reference count drops to zero.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 11, 2026
Last Updated Sep 14, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new high vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Linux / Linux
33f341c1fc60e172a3515c51bdabee11e83d1ee9 < a7ecd1a04f4f485d7be6443d0f0b2c61a800cb82 b131989797f7287d7fdadb2bababc05a15d44750 < f983793f03148b097977f200298db215cd2d4438 3bc7324e4911351e39c54a62e6ca46321cb10faf < 6f46762196f04464e1050a9ee94e72b917db9010 6c67ed9ad9b83e453e808f9b31a931a20a25629b < 891a8d11f4d5eb50b2ce7570f4f98204a7a57493 6c67ed9ad9b83e453e808f9b31a931a20a25629b < c74ff0b1a0fca53d3ac185873c87d6a719b30a47 6c67ed9ad9b83e453e808f9b31a931a20a25629b < 4e747c864a88537e18b1ffc19a1954c9686bb8e1 6c67ed9ad9b83e453e808f9b31a931a20a25629b < 79a92896e2bb9471550c56fc23d8d93592f04c27 6c67ed9ad9b83e453e808f9b31a931a20a25629b < 858965947081d10d41d9a1010a540d3d5eea958b 3e016ef2e72da93a2ea7afbb45de1b481b44d761 3256e152b645fc1e788ba44c2d8ced690113e3e6 0eda2004f38d95ef5715d62be884cd344260535b 43ca70753dfffd517d2af126da28690f8f615605 5.10.177 < 5.10.270 5.15.105 < 5.15.221 6.1.22 < 6.1.188 4.14.312 < 4.15 4.19.280 < 4.20 5.4.240 < 5.5 6.2.9 < 6.3
Linux / Linux
6.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/a7ecd1a04f4f485d7be6443d0f0b2c61a800cb82 git.kernel.org: https://git.kernel.org/stable/c/f983793f03148b097977f200298db215cd2d4438 git.kernel.org: https://git.kernel.org/stable/c/6f46762196f04464e1050a9ee94e72b917db9010 git.kernel.org: https://git.kernel.org/stable/c/891a8d11f4d5eb50b2ce7570f4f98204a7a57493 git.kernel.org: https://git.kernel.org/stable/c/c74ff0b1a0fca53d3ac185873c87d6a719b30a47 git.kernel.org: https://git.kernel.org/stable/c/4e747c864a88537e18b1ffc19a1954c9686bb8e1 git.kernel.org: https://git.kernel.org/stable/c/79a92896e2bb9471550c56fc23d8d93592f04c27 git.kernel.org: https://git.kernel.org/stable/c/858965947081d10d41d9a1010a540d3d5eea958b