ALSA: caiaq: Fix potential double-free at error path

Summary

CVECVE-2026-98066
StatePUBLISHED
AssignerLinux
Source PriorityCVE Program / NVD first with legacy fallback
Published2026-09-25 11:17:35 UTC
Updated2026-09-25 11:17:35 UTC
DescriptionIn the Linux kernel, the following vulnerability has been resolved: ALSA: caiaq: Fix potential double-free at error path The fix for caiaq driver's resource management to handle the errors tries to release the resources in a common destructor call, but as a sashiko review for another patch suggested, some of the audio resources such as URBs have been already freed, and this may lead to a double-free. For addressing the double-free, call the common destructor function from each place, and assure that the resource pointers get cleared.

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Linux Linux affected 6251e3e256337a30160ef59ab1580dde4d1acd28 2883d65a3d9a8d9a682cdb003e6ab7fb28bb17f8 git Not specified
CNA Linux Linux affected e59ecd4ee3a450db6cb4e4ecaa3efdd593f80056 1dd715ca0568e4833ed5878f49b028b449941096 git Not specified
CNA Linux Linux affected 28abd224db4a49560b452115bca3672a20e45b2f b629ae7b3eddc6812d5af3614b8c1bd76d65fa75 git Not specified
CNA Linux Linux affected 28abd224db4a49560b452115bca3672a20e45b2f 3b26ceef88c110f4d188387cffa0df78657be904 git Not specified
CNA Linux Linux affected da938aa9fc7826901921dcea225948ab21a97e45 git Not specified
CNA Linux Linux affected 09616e25f502080ba684fc7fcf959d1376ab756d git Not specified
CNA Linux Linux affected b956e48371f2ff72b76be9a829800ecec963bd45 git Not specified
CNA Linux Linux affected f537e3ad69609f6924a4db6b4a7f6561f5288bdd git Not specified
CNA Linux Linux affected 096dd8519cf2f768e9e14f224b627f7aaee1a9c5 git Not specified
CNA Linux Linux affected 6.12.86 6.12.111 semver Not specified
CNA Linux Linux affected 6.18.27 6.18.53 semver Not specified
CNA Linux Linux affected 5.10.258 5.11 semver Not specified
CNA Linux Linux affected 5.15.209 5.16 semver Not specified
CNA Linux Linux affected 6.1.175 6.2 semver Not specified
CNA Linux Linux affected 6.6.140 6.7 semver Not specified
CNA Linux Linux affected 7.0.4 7.1 semver Not specified
CNA Linux Linux affected 7.1 Not specified
CNA Linux Linux unaffected 7.1 semver Not specified
CNA Linux Linux unaffected 6.12.111 6.12.* semver Not specified
CNA Linux Linux unaffected 6.18.53 6.18.* semver Not specified
CNA Linux Linux unaffected 7.2.7 7.2.* semver Not specified
CNA Linux Linux unaffected 7.3-rc2 * original_commit_for_fix Not specified

References

ReferenceSourceLinkTags
git.kernel.org/stable/c/1dd715ca0568e4833ed5878f49b028b449941096 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/3b26ceef88c110f4d188387cffa0df78657be904 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/2883d65a3d9a8d9a682cdb003e6ab7fb28bb17f8 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/b629ae7b3eddc6812d5af3614b8c1bd76d65fa75 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report