CVE-2026-98066 PUBLISHED

ALSA: caiaq: Fix potential double-free at error path

Assigner: Linux
Reserved: 25.09.2026 Published: 25.09.2026 Updated: 25.09.2026

In the Linux kernel, the following vulnerability has been resolved:

ALSA: caiaq: Fix potential double-free at error path

The fix for caiaq driver's resource management to handle the errors tries to release the resources in a common destructor call, but as a sashiko review for another patch suggested, some of the audio resources such as URBs have been already freed, and this may lead to a double-free.

For addressing the double-free, call the common destructor function from each place, and assure that the resource pointers get cleared.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 6251e3e256337a30160ef59ab1580dde4d1acd28 to 2883d65a3d9a8d9a682cdb003e6ab7fb28bb17f8 (excl.)
  • affected from e59ecd4ee3a450db6cb4e4ecaa3efdd593f80056 to 1dd715ca0568e4833ed5878f49b028b449941096 (excl.)
  • affected from 28abd224db4a49560b452115bca3672a20e45b2f to b629ae7b3eddc6812d5af3614b8c1bd76d65fa75 (excl.)
  • affected from 28abd224db4a49560b452115bca3672a20e45b2f to 3b26ceef88c110f4d188387cffa0df78657be904 (excl.)
  • Version da938aa9fc7826901921dcea225948ab21a97e45 is affected
  • Version 09616e25f502080ba684fc7fcf959d1376ab756d is affected
  • Version b956e48371f2ff72b76be9a829800ecec963bd45 is affected
  • Version f537e3ad69609f6924a4db6b4a7f6561f5288bdd is affected
  • Version 096dd8519cf2f768e9e14f224b627f7aaee1a9c5 is affected
  • affected from 6.12.86 to 6.12.111 (excl.)
  • affected from 6.18.27 to 6.18.53 (excl.)
  • affected from 5.10.258 to 5.11 (excl.)
  • affected from 5.15.209 to 5.16 (excl.)
  • affected from 6.1.175 to 6.2 (excl.)
  • affected from 6.6.140 to 6.7 (excl.)
  • affected from 7.0.4 to 7.1 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 7.1 is affected
  • unaffected from 0 to 7.1 (excl.)
  • unaffected from 6.12.111 to 6.12.* (incl.)
  • unaffected from 6.18.53 to 6.18.* (incl.)
  • unaffected from 7.2.7 to 7.2.* (incl.)
  • unaffected from 7.3-rc2 to * (incl.)

References