CVE-2026-98066
N/A
N/A
Summary
In the Linux kernel, the following vulnerability has been resolved:
ALSA: caiaq: Fix potential double-free at error path
The fix for caiaq driver's resource management to handle the errors tries to release the resources in a common destructor call, but as a sashiko review for another patch suggested, some of the audio resources such as URBs have been already freed, and this may lead to a double-free.
For addressing the double-free, call the common destructor function from each place, and assure that the resource pointers get cleared.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 6251e3e256337a30160ef59ab1580dde4d1acd28 < 2883d65a3d9a8d9a682cdb003e6ab7fb28bb17f8 | affected |
| Linux | Linux | e59ecd4ee3a450db6cb4e4ecaa3efdd593f80056 < 1dd715ca0568e4833ed5878f49b028b449941096 | affected |
| Linux | Linux | 28abd224db4a49560b452115bca3672a20e45b2f < b629ae7b3eddc6812d5af3614b8c1bd76d65fa75 | affected |
| Linux | Linux | 28abd224db4a49560b452115bca3672a20e45b2f < 3b26ceef88c110f4d188387cffa0df78657be904 | affected |
| Linux | Linux | da938aa9fc7826901921dcea225948ab21a97e45 | affected |
| Linux | Linux | 09616e25f502080ba684fc7fcf959d1376ab756d | affected |
| Linux | Linux | b956e48371f2ff72b76be9a829800ecec963bd45 | affected |
| Linux | Linux | f537e3ad69609f6924a4db6b4a7f6561f5288bdd | affected |
| Linux | Linux | 096dd8519cf2f768e9e14f224b627f7aaee1a9c5 | affected |
| Linux | Linux | 6.12.86 < 6.12.111 | affected |
| Linux | Linux | 6.18.27 < 6.18.53 | affected |
| Linux | Linux | 5.10.258 < 5.11 | affected |
| Linux | Linux | 5.15.209 < 5.16 | affected |
| Linux | Linux | 6.1.175 < 6.2 | affected |
| Linux | Linux | 6.6.140 < 6.7 | affected |
| Linux | Linux | 7.0.4 < 7.1 | affected |
| Linux | Linux | 7.1 | affected |
| Linux | Linux | 0 < 7.1 | unaffected |
| Linux | Linux | 6.12.111 <= 6.12.* | unaffected |
| Linux | Linux | 6.18.53 <= 6.18.* | unaffected |
| Linux | Linux | 7.2.7 <= 7.2.* | unaffected |
| Linux | Linux | 7.3-rc2 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/2883d65a3d9a8d9a682cdb003e6ab7fb28bb17f8
- https://git.kernel.org/stable/c/1dd715ca0568e4833ed5878f49b028b449941096
- https://git.kernel.org/stable/c/b629ae7b3eddc6812d5af3614b8c1bd76d65fa75
- https://git.kernel.org/stable/c/3b26ceef88c110f4d188387cffa0df78657be904
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.