CVE-2026-98266
In the Linux kernel, the following vulnerability has been resolved: ALSA: core: Fix potential UAF after asynchronous card release Usually a sound driver releases the resources assigned to the card via snd_card_free(), and it synchronizes with the whole release procedure. However, when the card is released asynchronously via snd_card_free_when_closed() like USB-audio driver, the situation is slightly different; although the snd_card_disconnect() call at the disconnection guarantees that any newer accesses will be gated, the in-flight tasks might be still accessing to the underlying card->dev device even after the disconnection, which would cause a use-after-free in the end, as reported by fuzzers. For addressing the bug above, this patch takes the refcount of card->dev at initialization of the card object, and releases at its destructor. This assures the availability of the card->dev in its whole lifecycle.
Affected versions
Linux kernel versions
2.6.12
and later are affected. Fixed in
6.12.112,
6.18.54,
7.2.8,
7.3-rc4
and their respective stable series.
References
4 totalFrequently asked questions
-
What is CVE-2026-98266?
CVE-2026-98266 is a unscored severity Linux kernel vulnerability . It affects Linux kernel versions from 2.6.12 onward and has been patched in 6.12.112, 6.18.54, 7.2.8 and others. CVE-2026-98266 has not been confirmed as actively exploited and is not listed in the CISA KEV catalog.
-
Is there a patch available for CVE-2026-98266?
Yes. CVE-2026-98266 has been patched. Fixed versions include 6.12.112, 6.18.54, 7.2.8 and others. If you are running Linux kernel 2.6.12 or later up to the fix versions, apply the relevant patch for your kernel branch.
-
Is CVE-2026-98266 actively exploited?
No. CVE-2026-98266 has not been confirmed as actively exploited. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.