Linux Kernel Vulnerability in ALSA HDA TAS2781 Driver
CVE-2026-80872
What is CVE-2026-80872?
The Linux kernel has a vulnerability in the ALSA HDA TAS2781 driver that affects firmware loading procedures during device unbinding. This issue arises when the firmware loader's callback module retains a reference even after the callback state begins to be removed. If the firmware callback runs after the unbinding has commenced, it may operate on state that is in the process of being dismantled, potentially leading to undefined behavior or system instability. Proper cancellation or synchronization of the async firmware requests should be implemented before removing device controls and DSP states to mitigate this risk.
Affected Version(s)
Linux 5be27f1e3ec98975c18a91e220d4847d0dec9671
Linux 5be27f1e3ec98975c18a91e220d4847d0dec9671
Linux 5be27f1e3ec98975c18a91e220d4847d0dec9671 < 5367e2ad14f0ae9350a7aaf2e77c87de39a43ae9