Linux Kernel Vulnerability in ALSA HDA TAS2781 Driver
CVE-2026-80872

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
4 September 2026

What is CVE-2026-80872?

The Linux kernel has a vulnerability in the ALSA HDA TAS2781 driver that affects firmware loading procedures during device unbinding. This issue arises when the firmware loader's callback module retains a reference even after the callback state begins to be removed. If the firmware callback runs after the unbinding has commenced, it may operate on state that is in the process of being dismantled, potentially leading to undefined behavior or system instability. Proper cancellation or synchronization of the async firmware requests should be implemented before removing device controls and DSP states to mitigate this risk.

Affected Version(s)

Linux 5be27f1e3ec98975c18a91e220d4847d0dec9671

Linux 5be27f1e3ec98975c18a91e220d4847d0dec9671

Linux 5be27f1e3ec98975c18a91e220d4847d0dec9671 < 5367e2ad14f0ae9350a7aaf2e77c87de39a43ae9

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.