Description
In the Linux kernel, the following vulnerability has been resolved:

ASoC: xilinx: formatter_pcm: fix stream_data leak on open error

In xlnx_formatter_pcm_open(), stream_data is allocated and
adata->play_stream or adata->capture_stream is assigned early. If a
later step, such as snd_pcm_hw_constraint_step() or
snd_pcm_hw_constraint_integer(), fails, the function returns the error
immediately. ALSA does not call the close callback when open fails, so
stream_data is leaked and the stream pointer is left dangling, pointing
to a substream that ALSA frees. A later interrupt would then call
snd_pcm_period_elapsed() on the freed substream.

Free stream_data and clear the stream pointer on the error paths.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Potential Use-After-Free leading to kernel crash or privilege escalation
Action: Patch Now
AI Analysis

Impact

An ASoc Xilinx formatter PCM driver in the Linux kernel allocates stream data early during open and assigns it to a substream pointer. If a subsequent hardware constraint call fails, the driver returns immediately without freeing the allocated structure. The ALSA subsystem does not invoke a close callback for a failed open, leaving the stream pointer dangling. When an interrupt later triggers the period elapsed handler, it accesses the freed substream, causing a use-after-free condition that can crash the kernel or provide a foothold for code execution. This flaw maps to CWE-416, the use-after-free weakness.

Affected Systems

The vulnerability resides in the Linux kernel’s ASoc Xilinx formatter PCM driver. All kernel releases lacking the patch that clears stream_data on error are affected. No specific vendor or product sub-versions are listed, so the issue applies broadly to any Linux kernel that includes the older Xilinx driver code.

Risk and Exploitability

The EPSS score is below 1% and the flaw is not listed in CISA KEV, indicating a low likelihood of widespread exploitation. The weakness requires a local user with ability to open the PCM device, so the attack vector is local. Although the unpatched code can result in a kernel crash or potential privilege escalation, the absence of a public exploit and the restrictive user context suggest remediation priority is medium; nevertheless a patch should be applied as soon as possible.

Generated by OpenCVE AI on September 20, 2026 at 01:26 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the kernel patch that frees stream_data on error paths and clears the stream pointer
  • If unable to update the kernel, blacklist or disable the Xilinx ALSA formatter PCM driver to prevent the use-after-free condition
  • Monitor system logs for kernel crashes or unusual suspend/resume activity that may indicate a pending use-after-free exploitation attempt

Generated by OpenCVE AI on September 20, 2026 at 01:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sun, 20 Sep 2026 01:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-401
CWE-416

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: ASoC: xilinx: formatter_pcm: fix stream_data leak on open error In xlnx_formatter_pcm_open(), stream_data is allocated and adata->play_stream or adata->capture_stream is assigned early. If a later step, such as snd_pcm_hw_constraint_step() or snd_pcm_hw_constraint_integer(), fails, the function returns the error immediately. ALSA does not call the close callback when open fails, so stream_data is leaked and the stream pointer is left dangling, pointing to a substream that ALSA frees. A later interrupt would then call snd_pcm_period_elapsed() on the freed substream. Free stream_data and clear the stream pointer on the error paths.
Title ASoC: xilinx: formatter_pcm: fix stream_data leak on open error
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:07:27.407Z

Reserved: 2026-09-11T19:38:34.793Z

Link: CVE-2026-90214

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:16.650

Modified: 2026-09-17T17:17:16.650

Link: CVE-2026-90214

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T01:30:16Z

Weaknesses
  • CWE-401

    Missing Release of Memory after Effective Lifetime

  • CWE-416

    Use After Free