{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-89736","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.761Z","datePublished":"2026-09-11T19:46:44.608Z","dateUpdated":"2026-09-14T12:02:23.539Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-14T12:02:23.539Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget: u_audio: Fix use-after-free on sound card disconnect\n\ng_audio_cleanup() invokes snd_card_free_when_closed() to initiate sound\ncard teardown and immediately frees the underlying struct snd_uac_chip\ncontext. However, snd_card_free_when_closed() returns asynchronously\nwhile ALSA control elements (kctls) remain open in userspace.\n\nWhen userspace control applications access or close these open file\ndescriptors, kctl callbacks attempt to dereference kctl->private_data\npointing to &uac->c_prm or &uac->p_prm within the freed uac structure,\nresulting in a use-after-free (UAF) memory corruption.\n\nFix this issue by deferring the destruction of struct snd_uac_chip until\nall references to the ALSA sound card are released. Register a custom\ncard->private_free callback (u_audio_card_free) during g_audio_setup()\nthat frees uac and its associated playback/capture request and ring\nbuffers only when the sound card reference count drops to zero."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The UAF is reached from local userspace: configfs UDC unbind calls afunc_unbind/f_audio_unbind → g_audio_cleanup, which frees snd_uac_chip while ALSA kctl/PCM fds still reference it; g_audio_setup runs at function bind with no USB host required, matching gadget teardown scores such as CVE-2024-38628.\nAC:L - The attacker controls both sides by issuing SNDRV_CTL_IOCTL_ELEM_READ/WRITE on the UAC mixer kctls while concurrently unbinding the gadget; snd_card_disconnect does not drain in-flight ioctls before g_audio_cleanup kfree()s the chip, so kctl get/put callbacks dereference freed uac_rtd_params and the race is freely retryable.\nPR:L - Android and embedded USB gadget HALs commonly delegate /sys/kernel/config/usb_gadget UDC writes to non-root service accounts, and the UAC gadget's ALSA control/PCM nodes are reachable by unprivileged local users; init-namespace root is not required once the gadget is deployed.\nUI:N - The attacker performs gadget unbind, holds ALSA fds, and issues mixer ioctls itself; no separate victim action such as plugging a cable or mounting a filesystem is required.\nS:U - The use-after-free corrupts kernel heap objects (snd_uac_chip and its playback/capture rings) within the same host kernel security authority; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - Kctl get/info/tlv callbacks (u_audio_volume_get, u_audio_rate_get, u_audio_volume_tlv) read volume, rate, and TLV fields from the already-freed snd_uac_chip and copy them to userspace, yielding a use-after-free disclosure primitive that kernel scoring treats as High confidentiality.\nI:H - Kctl put callbacks (u_audio_volume_put, u_audio_mute_put, u_audio_pitch_put) take prm->lock and write volume/mute/pitch into the kfree()'d snd_uac_chip, providing a write-after-free primitive that can be turned into arbitrary write or control-flow hijack.\nA:H - Use of the freed snd_uac_chip, including spin_lock_irqsave on prm->lock and USB ISO completions with req->context pointing into the freed object, reliably produces KASAN reports, oops, and kernel panic."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/usb/gadget/function/u_audio.c"],"versions":[{"version":"33f341c1fc60e172a3515c51bdabee11e83d1ee9","lessThan":"a7ecd1a04f4f485d7be6443d0f0b2c61a800cb82","status":"affected","versionType":"git"},{"version":"b131989797f7287d7fdadb2bababc05a15d44750","lessThan":"f983793f03148b097977f200298db215cd2d4438","status":"affected","versionType":"git"},{"version":"3bc7324e4911351e39c54a62e6ca46321cb10faf","lessThan":"6f46762196f04464e1050a9ee94e72b917db9010","status":"affected","versionType":"git"},{"version":"6c67ed9ad9b83e453e808f9b31a931a20a25629b","lessThan":"891a8d11f4d5eb50b2ce7570f4f98204a7a57493","status":"affected","versionType":"git"},{"version":"6c67ed9ad9b83e453e808f9b31a931a20a25629b","lessThan":"c74ff0b1a0fca53d3ac185873c87d6a719b30a47","status":"affected","versionType":"git"},{"version":"6c67ed9ad9b83e453e808f9b31a931a20a25629b","lessThan":"4e747c864a88537e18b1ffc19a1954c9686bb8e1","status":"affected","versionType":"git"},{"version":"6c67ed9ad9b83e453e808f9b31a931a20a25629b","lessThan":"79a92896e2bb9471550c56fc23d8d93592f04c27","status":"affected","versionType":"git"},{"version":"6c67ed9ad9b83e453e808f9b31a931a20a25629b","lessThan":"858965947081d10d41d9a1010a540d3d5eea958b","status":"affected","versionType":"git"},{"version":"3e016ef2e72da93a2ea7afbb45de1b481b44d761","status":"affected","versionType":"git"},{"version":"3256e152b645fc1e788ba44c2d8ced690113e3e6","status":"affected","versionType":"git"},{"version":"0eda2004f38d95ef5715d62be884cd344260535b","status":"affected","versionType":"git"},{"version":"43ca70753dfffd517d2af126da28690f8f615605","status":"affected","versionType":"git"},{"version":"5.10.177","lessThan":"5.10.270","status":"affected","versionType":"semver"},{"version":"5.15.105","lessThan":"5.15.221","status":"affected","versionType":"semver"},{"version":"6.1.22","lessThan":"6.1.188","status":"affected","versionType":"semver"},{"version":"4.14.312","lessThan":"4.15","status":"affected","versionType":"semver"},{"version":"4.19.280","lessThan":"4.20","status":"affected","versionType":"semver"},{"version":"5.4.240","lessThan":"5.5","status":"affected","versionType":"semver"},{"version":"6.2.9","lessThan":"6.3","status":"affected","versionType":"semver"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/usb/gadget/function/u_audio.c"],"versions":[{"version":"6.3","status":"affected"},{"version":"0","lessThan":"6.3","status":"unaffected","versionType":"semver"},{"version":"5.10.270","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.221","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.188","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.157","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.109","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.50","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.4","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.10.177","versionEndExcluding":"5.10.270"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.15.105","versionEndExcluding":"5.15.221"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.1.22","versionEndExcluding":"6.1.188"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.3","versionEndExcluding":"6.6.157"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.3","versionEndExcluding":"6.12.109"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.3","versionEndExcluding":"6.18.50"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.3","versionEndExcluding":"7.2.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.3","versionEndExcluding":"7.3-rc1"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.14.312"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.19.280"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.4.240"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.2.9"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/a7ecd1a04f4f485d7be6443d0f0b2c61a800cb82"},{"url":"https://git.kernel.org/stable/c/f983793f03148b097977f200298db215cd2d4438"},{"url":"https://git.kernel.org/stable/c/6f46762196f04464e1050a9ee94e72b917db9010"},{"url":"https://git.kernel.org/stable/c/891a8d11f4d5eb50b2ce7570f4f98204a7a57493"},{"url":"https://git.kernel.org/stable/c/c74ff0b1a0fca53d3ac185873c87d6a719b30a47"},{"url":"https://git.kernel.org/stable/c/4e747c864a88537e18b1ffc19a1954c9686bb8e1"},{"url":"https://git.kernel.org/stable/c/79a92896e2bb9471550c56fc23d8d93592f04c27"},{"url":"https://git.kernel.org/stable/c/858965947081d10d41d9a1010a540d3d5eea958b"}],"title":"usb: gadget: u_audio: Fix use-after-free on sound card disconnect","x_generator":{"engine":"bippy-1.2.0"}}}}