Description
In the Linux kernel, the following vulnerability has been resolved:

usb: gadget: u_audio: Fix use-after-free on sound card disconnect

g_audio_cleanup() invokes snd_card_free_when_closed() to initiate sound
card teardown and immediately frees the underlying struct snd_uac_chip
context. However, snd_card_free_when_closed() returns asynchronously
while ALSA control elements (kctls) remain open in userspace.

When userspace control applications access or close these open file
descriptors, kctl callbacks attempt to dereference kctl->private_data
pointing to &uac->c_prm or &uac->p_prm within the freed uac structure,
resulting in a use-after-free (UAF) memory corruption.

Fix this issue by deferring the destruction of struct snd_uac_chip until
all references to the ALSA sound card are released. Register a custom
card->private_free callback (u_audio_card_free) during g_audio_setup()
that frees uac and its associated playback/capture request and ring
buffers only when the sound card reference count drops to zero.
Published: 2026-09-11
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Kernel memory corruption leading to privilege escalation
Action: Apply patch immediately
AI Analysis

Impact

The u_audio USB gadget driver contains a use‑after‑free flaw (CWE‑825). When a sound card is disconnected while a userspace ALSA control element remains open, the driver before all ALSA references are released. Subsequent callbacks then dereference memorying kernel data and potentially allowing an attacker to execute arbitrary code with kernel privileges.

Affected Systems

All Linux kernel builds that include the u_audio gadget driver are affected. The vulnerability applies to both default kernel configurations and custom builds that enable the driver, whether it is compiled into the kernel or loaded as a module.

Risk and Exploitability

The vulnerability’s CVSS score of 7.8 indicates moderate to high severity. The EPSS of less than 1 % suggests a low current exploitation likelihood, and the flaw is not listed in CISA’s KEV catalog. Exploitation requires a local attacker to control the USB device, trigger a disconnect while a userspace control descriptor remains open, and then generate callbacks that access freed memory. If successful, the attacker could gain kernel‑level execution on the affected system.

Generated by OpenCVE AI on September 15, 2026 at 19:20 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the kernel to a version that includes the u_audio use‑after‑free fix.
  • Reboot the system to load the updated kernel and unload any residual old u_audio driver modules.
  • If an immediate kernel update cannot be performed, disable or remove the USB audio gadget device or unload the u_audio module until the patch can be applied.

Generated by OpenCVE AI on September 15, 2026 at 19:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 14 Sep 2026 12:30:00 +0000


Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.0, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-825
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.0, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}

threat_severity

Important


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: usb: gadget: u_audio: Fix use-after-free on sound card disconnect g_audio_cleanup() invokes snd_card_free_when_closed() to initiate sound card teardown and immediately frees the underlying struct snd_uac_chip context. However, snd_card_free_when_closed() returns asynchronously while ALSA control elements (kctls) remain open in userspace. When userspace control applications access or close these open file descriptors, kctl callbacks attempt to dereference kctl->private_data pointing to &uac->c_prm or &uac->p_prm within the freed uac structure, resulting in a use-after-free (UAF) memory corruption. Fix this issue by deferring the destruction of struct snd_uac_chip until all references to the ALSA sound card are released. Register a custom card->private_free callback (u_audio_card_free) during g_audio_setup() that frees uac and its associated playback/capture request and ring buffers only when the sound card reference count drops to zero.
Title usb: gadget: u_audio: Fix use-after-free on sound card disconnect
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-14T12:02:23.539Z

Reserved: 2026-09-11T19:38:34.761Z

Link: CVE-2026-89736

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:20:04.077

Modified: 2026-09-14T13:19:22.700

Link: CVE-2026-89736

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-11T19:46:44Z

Links: CVE-2026-89736 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T19:30:12Z

Weaknesses
  • CWE-825

    Expired Pointer Dereference