Vulnerability in Linux Kernel Affecting ALSA and Audio Applications
CVE-2026-80716

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
28 August 2026

What is CVE-2026-80716?

In the Linux kernel, a vulnerability exists within the Advanced Linux Sound Architecture (ALSA). This issue leads to improper handling of linked streams during the drain process. Specifically, the function snd_pcm_drain() may park a wait entry on a drained peer’s runtime sleep but fails to remove it correctly if group membership changes before completion. This results in potential memory access violations due to attempts to wake a freed stack frame. The flaw is particularly concerning as it can be triggered by unlinking streams, which may lead to unexpected behavior in audio applications relying heavily on ALSA. The situation is further exacerbated as the wake-up mechanism does not function properly, allowing queued entries to persist incorrectly, thus posing a risk to system stability. It is crucial for users and administrators to apply updates to mitigate this vulnerability.

Affected Version(s)

Linux f57f3df03a8e6010e321fa0258d3e054713c3cb7

Linux f57f3df03a8e6010e321fa0258d3e054713c3cb7 < 3035bb784cea3f338934f5042dd3f35225a51b2e

Linux f57f3df03a8e6010e321fa0258d3e054713c3cb7 < 1c1b7e8e545ce65e40f65b55c432765e058ea98f

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.