Vulnerability in Linux Kernel Affects ALSA Controls in Intel HDA Audio Drivers
CVE-2026-64481
What is CVE-2026-64481?
The Linux kernel's ALSA controls, specifically in the Intel HDA audio drivers, exhibit vulnerabilities due to improper resource management. The cs35l41_hda component creates ALSA controls that reference driver data, which may become invalid if firmware loading activities are attempted post device removal. This occurs particularly when the DSP initialization is incomplete, leading to potential dereferencing of stale pointers. The flaw has been addressed by ensuring that created controls are properly removed during component unbinding, preventing the execution of callbacks that may interact with deallocated driver state. Additionally, queued firmware load requests are canceled during the removal process to mitigate any risks associated with running outdated work items.
Affected Version(s)
Linux 47ceabd99a28399f8971f4ca0a37ebc0a21dd2a8 < 8947215c0136c9d905e4a46d824824f8b48a2e5b
Linux 47ceabd99a28399f8971f4ca0a37ebc0a21dd2a8
Linux 47ceabd99a28399f8971f4ca0a37ebc0a21dd2a8