Description
In the Linux kernel, the following vulnerability has been resolved:

media: cobalt: Avoid freeing ALSA private data twice

snd_cobalt_card_create() stores cobsc in sc->private_data and installs
snd_cobalt_card_private_free() as sc->private_free. From that point,
snd_card_free(sc) releases cobsc through the ALSA card cleanup path.

If cobalt_alsa_init() fails after snd_cobalt_card_create(), the
err_exit_free path calls snd_card_free(sc) and then kfree(cobsc). That
second free releases the same object again.

Remove the explicit kfree(cobsc) and leave ownership with the ALSA card.

This issue was found by a static analysis checker and confirmed by
manual source review.
Published: 2026-09-16
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Double free leading to memory corruption
Action: Patch
AI Analysis

Impact

During media driver initialization the kernel allocates an object for the Cobalt audio device and registers a free callback. If initialization fails after the object is allocated, the code frees it twice: once through the ALSA card cleanup path and again manually. This double‑free can corrupt kernel memory and, while an exploitation path is not detailed in the description, such a flaw could allow privilege escalation or system instability if an attacker can trigger the failure scenario. The flaw is identified as CWE‑416, a classic use‑after‑free weakness. Based on the description, it is inferred that an attacker could trigger the failure by supplying malformed audio data during device initialization, implying a local privilege escalation vector via the driver.

Affected Systems

The vulnerability affects the Linux kernel’s media subsystem, specifically the cobalt driver. All kernel versions prior to the fix are potentially impacted; the exact version range is not specified, but any kernel containing the flawed code path is vulnerable.

Risk and Exploitability

The EPSS score is reported as less than 1 percent, indicating a low probability of exploitation, and the vulnerability is not listed in CISA's KEV catalog. However double‑free bugs in the kernel are often considered severe because they can lead to privilege escalation. Based on the description, it is inferred that exploitation would require an attacker to induce initialization failure, possibly through crafted input to the cobalt driver, which suggests a local target attack scenario. In the absence of a publicly documented exploit, the risk is moderate but should be treated with caution, especially in environments where kernel stability is critical.

Generated by OpenCVE AI on September 18, 2026 at 09:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update to the latest stable Linux kernel that incorporates the fix referenced by commit 3a7d6b9c4cb5ac18cbd3f1c7f8c7b159c42ba0b1
  • If an update is not immediately possible, manually patch the cobalt driver source by removing the explicit kfree(cobsc) as described in the kernel patch notes and rebuild the kernel
  • Restart the system to ensure the patched driver is loaded and verify that the double‑free path has been eliminated

Generated by OpenCVE AI on September 18, 2026 at 09:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Fri, 18 Sep 2026 09:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: media: cobalt: Avoid freeing ALSA private data twice snd_cobalt_card_create() stores cobsc in sc->private_data and installs snd_cobalt_card_private_free() as sc->private_free. From that point, snd_card_free(sc) releases cobsc through the ALSA card cleanup path. If cobalt_alsa_init() fails after snd_cobalt_card_create(), the err_exit_free path calls snd_card_free(sc) and then kfree(cobsc). That second free releases the same object again. Remove the explicit kfree(cobsc) and leave ownership with the ALSA card. This issue was found by a static analysis checker and confirmed by manual source review.
Title media: cobalt: Avoid freeing ALSA private data twice
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T10:31:56.817Z

Reserved: 2026-09-11T19:38:34.773Z

Link: CVE-2026-89895

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:16:58.270

Modified: 2026-09-16T11:16:58.270

Link: CVE-2026-89895

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T09:30:06Z

Weaknesses