Description
In the Linux kernel, the following vulnerability has been resolved:

media: go7007: defer the ALSA v4l2 put until card release

go7007_snd_init() already takes a v4l2_device reference for the ALSA
side, but go7007_snd_remove() drops it immediately after calling
snd_card_free_when_closed().

That is too early when a userspace process still has the capture PCM open.
The ALSA card and its PCM callbacks remain alive until the last file is
closed, so the release path can still reach struct go7007 through
pcm->private_data and call go7007_snd_hw_free() after the V4L2 release path
has freed the object.

Move the matching v4l2_device_put() to the ALSA card private_free callback
so the existing ALSA reference covers the whole deferred card lifetime.
Published: 2026-09-16
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Use‑After‑Free in the Linux kernel ALSA integration
Action: Patch
AI Analysis

Impact

The flaw originates from an early release of a v4l2_device reference in the go7007 driver while a userspace process still holds an open PCM capture. The go7007_snd_remove() routine drops the reference immediately after calling snd_card_free_when_closed(), which can occur before the V4L2 release path has fully finished cleaning up. This allows the kernel’s ALSA callbacks to access freed memory and trigger a use‑after‑free condition that could crash the kernel or allow an attacker to execute code in kernel mode if the freed memory is reused maliciously.

Affected Systems

All Linux kernel installations that contain the go7007 driver are affected. Specific kernel version ranges are not listed in the CVE data, so any actively maintained kernel that includes this driver should be examined for the pending fix.

Risk and Exploitability

The CVSS score of 7.8 indicates high severity. The EPSS score of <1% suggests exploitation is unlikely at present, and the vulnerability is not listed in CISA’s KEV catalog. Because the fault can be triggered by a local user who opens a PCM capture, the attack vector is local privilege or a local software component that has permission to access the device. A successful exploitation could lead to a kernel crash or privilege escalation to arbitrary kernel execution.

Generated by OpenCVE AI on September 18, 2026 at 08:38 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to a kernel version that includes the patch that defers the v4l2_device_put to the ALSA card's private_free callback.
  • Temporarily unload or disable the go7007 driver on systems that do not yet have the updated kernel.
  • Restrict access to the capture PCM device by applying udev rules or adjusting file permissions to prevent unprivileged users from opening it.

Generated by OpenCVE AI on September 18, 2026 at 08:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Fri, 18 Sep 2026 09:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: media: go7007: defer the ALSA v4l2 put until card release go7007_snd_init() already takes a v4l2_device reference for the ALSA side, but go7007_snd_remove() drops it immediately after calling snd_card_free_when_closed(). That is too early when a userspace process still has the capture PCM open. The ALSA card and its PCM callbacks remain alive until the last file is closed, so the release path can still reach struct go7007 through pcm->private_data and call go7007_snd_hw_free() after the V4L2 release path has freed the object. Move the matching v4l2_device_put() to the ALSA card private_free callback so the existing ALSA reference covers the whole deferred card lifetime.
Title media: go7007: defer the ALSA v4l2 put until card release
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T14:39:41.154Z

Reserved: 2026-09-11T19:38:34.773Z

Link: CVE-2026-89890

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:16:57.610

Modified: 2026-09-16T15:18:15.500

Link: CVE-2026-89890

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T08:45:07Z

Weaknesses