Memory Management Bug in Linux Kernel's USBTV Media Driver
CVE-2026-90032

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
16 September 2026

What is CVE-2026-90032?

A vulnerability in the Linux kernel's USBTV media driver can lead to improper memory management during operations involving ALSA PCM callbacks. When a USB audio device is disconnected while an open PCM file exists, it can cause a situation where the driver state is incorrectly handled. This results in a potential dereference of freed memory in the snd_usbtv_pcm_close() function, creating opportunities for exploitation. The vulnerability highlights the importance of maintaining valid device references and ensuring that resources are properly managed throughout the lifecycle of USB audio interactions.

Affected Version(s)

Linux 63ddf68de52efaac40a9287e44266ac30e71dd36 < 97b5e8b22b98e287481a97a9a4cfebbb348738a5

Linux 63ddf68de52efaac40a9287e44266ac30e71dd36 < 503be26ff888cb3576e55d251895d290e8146f27

Linux 63ddf68de52efaac40a9287e44266ac30e71dd36

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.