CVE-2026-98066
In the Linux kernel, the following vulnerability has been resolved: ALSA: caiaq: Fix potential double-free at error path The fix for caiaq driver's resource management to handle the errors tries to release the resources in a common destructor call, but as a sashiko review for another patch suggested, some of the audio resources such as URBs have been already freed, and this may lead to a double-free. For addressing the double-free, call the common destructor function from each place, and assure that the resource pointers get cleared.
Affected versions
Linux kernel versions
5.10.258,
5.15.209,
6.1.175,
6.6.140,
6.12.86,
6.18.27,
7.0.4,
7.1
and later are affected. Fixed in
5.10.271,
5.15.222,
6.1.189,
6.6.158,
6.12.111,
6.18.53,
7.2.7,
7.3-rc2
and their respective stable series.
References
8 totalFrequently asked questions
-
What is CVE-2026-98066?
CVE-2026-98066 is a unscored severity Linux kernel vulnerability . It affects Linux kernel versions from 5.10.258 onward and has been patched in 5.10.271, 5.15.222, 6.1.189 and others. CVE-2026-98066 has not been confirmed as actively exploited and is not listed in the CISA KEV catalog.
-
Is there a patch available for CVE-2026-98066?
Yes. CVE-2026-98066 has been patched. Fixed versions include 5.10.271, 5.15.222, 6.1.189 and others. If you are running Linux kernel 5.10.258 or later up to the fix versions, apply the relevant patch for your kernel branch.
-
Is CVE-2026-98066 actively exploited?
No. CVE-2026-98066 has not been confirmed as actively exploited. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.