{"api_version":"1","generated_at":"2026-09-17T23:31:48+00:00","cve":"CVE-2026-93039","urls":{"html":"https://cve.report/CVE-2026-93039","api":"https://cve.report/api/cve/CVE-2026-93039.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-93039","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-93039"},"summary":{"title":"ASoC: meson: Keep link pointers valid on realloc failure","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: meson: Keep link pointers valid on realloc failure\n\nmeson_card_reallocate_links() grows the DAI link and private data\narrays with two consecutive krealloc() calls and updates the owner\npointers only after both calls have succeeded.\n\nA successful krealloc() may move the data: it frees the old block and\nreturns a new one. When that happens for the link array and the second\nkrealloc() then fails, card->dai_link still points to the block that\nkrealloc() already freed, and the error path frees the new block too.\nThe probe error path then calls meson_card_clean_references(), which\ndereferences card->dai_link and kfree()s it again, resulting in a\nuse-after-free and a double free.\n\nCommit card->dai_link and card->num_links right after the first\nkrealloc() succeeds, so the pointer always refers to a valid allocation\nthat meson_card_clean_references() can walk and free. krealloc() with\n__GFP_ZERO zero-initializes the added entries, so walking them on the\nerror path is safe. With both failure paths reduced to a plain return,\ndrop the goto labels and the error message.","state":"PUBLISHED","assigner":"Linux","published_at":"2026-09-17 17:17:56","updated_at":"2026-09-17 17:17:56"},"problem_types":[],"metrics":[],"references":[{"url":"https://git.kernel.org/stable/c/0b30fbe6bf7cf6499b19dd886f466e7c9e820089","name":"https://git.kernel.org/stable/c/0b30fbe6bf7cf6499b19dd886f466e7c9e820089","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/8fec16898f184e5f8f8fdd09ff1ced2bd7ffc13d","name":"https://git.kernel.org/stable/c/8fec16898f184e5f8f8fdd09ff1ced2bd7ffc13d","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/de33afc57f24538186bccf4c4f6c65dd38634fd8","name":"https://git.kernel.org/stable/c/de33afc57f24538186bccf4c4f6c65dd38634fd8","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/1c1485343b7c1c39dab7ecb9cd16ba49fd0ce642","name":"https://git.kernel.org/stable/c/1c1485343b7c1c39dab7ecb9cd16ba49fd0ce642","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/41e92e0caa1fe3df2efaca346bfcaeb7fb9826ab","name":"https://git.kernel.org/stable/c/41e92e0caa1fe3df2efaca346bfcaeb7fb9826ab","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/5ed1b048527bebe4529eb6e01c34dcc5d97ba5fe","name":"https://git.kernel.org/stable/c/5ed1b048527bebe4529eb6e01c34dcc5d97ba5fe","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/8db0a0fc84e80aa9924e0833aef6cc95df94e5a7","name":"https://git.kernel.org/stable/c/8db0a0fc84e80aa9924e0833aef6cc95df94e5a7","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/2aaa41cf974f83a6fb105422bac4e2f107150774","name":"https://git.kernel.org/stable/c/2aaa41cf974f83a6fb105422bac4e2f107150774","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-93039","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-93039","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 7864a79f37b55769b817d5e6c5ae0ca4bfdba93b de33afc57f24538186bccf4c4f6c65dd38634fd8 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 7864a79f37b55769b817d5e6c5ae0ca4bfdba93b 1c1485343b7c1c39dab7ecb9cd16ba49fd0ce642 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 7864a79f37b55769b817d5e6c5ae0ca4bfdba93b 8db0a0fc84e80aa9924e0833aef6cc95df94e5a7 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 7864a79f37b55769b817d5e6c5ae0ca4bfdba93b 41e92e0caa1fe3df2efaca346bfcaeb7fb9826ab git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 7864a79f37b55769b817d5e6c5ae0ca4bfdba93b 0b30fbe6bf7cf6499b19dd886f466e7c9e820089 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 7864a79f37b55769b817d5e6c5ae0ca4bfdba93b 8fec16898f184e5f8f8fdd09ff1ced2bd7ffc13d git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 7864a79f37b55769b817d5e6c5ae0ca4bfdba93b 5ed1b048527bebe4529eb6e01c34dcc5d97ba5fe git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 7864a79f37b55769b817d5e6c5ae0ca4bfdba93b 2aaa41cf974f83a6fb105422bac4e2f107150774 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 4.19","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 4.19 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 5.10.270 5.10.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 5.15.221 5.15.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.1.188 6.1.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.6.157 6.6.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.12.110 6.12.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.18.52 6.18.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.2.6 7.2.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.3-rc1 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["sound/soc/meson/meson-card-utils.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"de33afc57f24538186bccf4c4f6c65dd38634fd8","status":"affected","version":"7864a79f37b55769b817d5e6c5ae0ca4bfdba93b","versionType":"git"},{"lessThan":"1c1485343b7c1c39dab7ecb9cd16ba49fd0ce642","status":"affected","version":"7864a79f37b55769b817d5e6c5ae0ca4bfdba93b","versionType":"git"},{"lessThan":"8db0a0fc84e80aa9924e0833aef6cc95df94e5a7","status":"affected","version":"7864a79f37b55769b817d5e6c5ae0ca4bfdba93b","versionType":"git"},{"lessThan":"41e92e0caa1fe3df2efaca346bfcaeb7fb9826ab","status":"affected","version":"7864a79f37b55769b817d5e6c5ae0ca4bfdba93b","versionType":"git"},{"lessThan":"0b30fbe6bf7cf6499b19dd886f466e7c9e820089","status":"affected","version":"7864a79f37b55769b817d5e6c5ae0ca4bfdba93b","versionType":"git"},{"lessThan":"8fec16898f184e5f8f8fdd09ff1ced2bd7ffc13d","status":"affected","version":"7864a79f37b55769b817d5e6c5ae0ca4bfdba93b","versionType":"git"},{"lessThan":"5ed1b048527bebe4529eb6e01c34dcc5d97ba5fe","status":"affected","version":"7864a79f37b55769b817d5e6c5ae0ca4bfdba93b","versionType":"git"},{"lessThan":"2aaa41cf974f83a6fb105422bac4e2f107150774","status":"affected","version":"7864a79f37b55769b817d5e6c5ae0ca4bfdba93b","versionType":"git"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["sound/soc/meson/meson-card-utils.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"4.19"},{"lessThan":"4.19","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"5.10.*","status":"unaffected","version":"5.10.270","versionType":"semver"},{"lessThanOrEqual":"5.15.*","status":"unaffected","version":"5.15.221","versionType":"semver"},{"lessThanOrEqual":"6.1.*","status":"unaffected","version":"6.1.188","versionType":"semver"},{"lessThanOrEqual":"6.6.*","status":"unaffected","version":"6.6.157","versionType":"semver"},{"lessThanOrEqual":"6.12.*","status":"unaffected","version":"6.12.110","versionType":"semver"},{"lessThanOrEqual":"6.18.*","status":"unaffected","version":"6.18.52","versionType":"semver"},{"lessThanOrEqual":"7.2.*","status":"unaffected","version":"7.2.6","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.3-rc1","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"5.10.270","versionStartIncluding":"4.19","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"5.15.221","versionStartIncluding":"4.19","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.1.188","versionStartIncluding":"4.19","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.6.157","versionStartIncluding":"4.19","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.12.110","versionStartIncluding":"4.19","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.18.52","versionStartIncluding":"4.19","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2.6","versionStartIncluding":"4.19","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.3-rc1","versionStartIncluding":"4.19","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: meson: Keep link pointers valid on realloc failure\n\nmeson_card_reallocate_links() grows the DAI link and private data\narrays with two consecutive krealloc() calls and updates the owner\npointers only after both calls have succeeded.\n\nA successful krealloc() may move the data: it frees the old block and\nreturns a new one. When that happens for the link array and the second\nkrealloc() then fails, card->dai_link still points to the block that\nkrealloc() already freed, and the error path frees the new block too.\nThe probe error path then calls meson_card_clean_references(), which\ndereferences card->dai_link and kfree()s it again, resulting in a\nuse-after-free and a double free.\n\nCommit card->dai_link and card->num_links right after the first\nkrealloc() succeeds, so the pointer always refers to a valid allocation\nthat meson_card_clean_references() can walk and free. krealloc() with\n__GFP_ZERO zero-initializes the added entries, so walking them on the\nerror path is safe. With both failure paths reduced to a plain return,\ndrop the goto labels and the error message."}],"providerMetadata":{"dateUpdated":"2026-09-17T16:10:32.812Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/de33afc57f24538186bccf4c4f6c65dd38634fd8"},{"url":"https://git.kernel.org/stable/c/1c1485343b7c1c39dab7ecb9cd16ba49fd0ce642"},{"url":"https://git.kernel.org/stable/c/8db0a0fc84e80aa9924e0833aef6cc95df94e5a7"},{"url":"https://git.kernel.org/stable/c/41e92e0caa1fe3df2efaca346bfcaeb7fb9826ab"},{"url":"https://git.kernel.org/stable/c/0b30fbe6bf7cf6499b19dd886f466e7c9e820089"},{"url":"https://git.kernel.org/stable/c/8fec16898f184e5f8f8fdd09ff1ced2bd7ffc13d"},{"url":"https://git.kernel.org/stable/c/5ed1b048527bebe4529eb6e01c34dcc5d97ba5fe"},{"url":"https://git.kernel.org/stable/c/2aaa41cf974f83a6fb105422bac4e2f107150774"}],"title":"ASoC: meson: Keep link pointers valid on realloc failure","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-93039","datePublished":"2026-09-17T16:10:32.812Z","dateReserved":"2026-09-17T15:57:05.657Z","dateUpdated":"2026-09-17T16:10:32.812Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-17 17:17:56","lastModifiedDate":"2026-09-17 17:17:56","problem_types":[],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"93039","Ordinal":"1","Title":"ASoC: meson: Keep link pointers valid on realloc failure","CVE":"CVE-2026-93039","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"93039","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: meson: Keep link pointers valid on realloc failure\n\nmeson_card_reallocate_links() grows the DAI link and private data\narrays with two consecutive krealloc() calls and updates the owner\npointers only after both calls have succeeded.\n\nA successful krealloc() may move the data: it frees the old block and\nreturns a new one. When that happens for the link array and the second\nkrealloc() then fails, card->dai_link still points to the block that\nkrealloc() already freed, and the error path frees the new block too.\nThe probe error path then calls meson_card_clean_references(), which\ndereferences card->dai_link and kfree()s it again, resulting in a\nuse-after-free and a double free.\n\nCommit card->dai_link and card->num_links right after the first\nkrealloc() succeeds, so the pointer always refers to a valid allocation\nthat meson_card_clean_references() can walk and free. krealloc() with\n__GFP_ZERO zero-initializes the added entries, so walking them on the\nerror path is safe. With both failure paths reduced to a plain return,\ndrop the goto labels and the error message.","Type":"Description","Title":"ASoC: meson: Keep link pointers valid on realloc failure"}]}}}