Description
In the Linux kernel, the following vulnerability has been resolved:

ASoC: meson: Keep link pointers valid on realloc failure

meson_card_reallocate_links() grows the DAI link and private data
arrays with two consecutive krealloc() calls and updates the owner
pointers only after both calls have succeeded.

A successful krealloc() may move the data: it frees the old block and
returns a new one. When that happens for the link array and the second
krealloc() then fails, card->dai_link still points to the block that
krealloc() already freed, and the error path frees the new block too.
The probe error path then calls meson_card_clean_references(), which
dereferences card->dai_link and kfree()s it again, resulting in a
use-after-free and a double free.

Commit card->dai_link and card->num_links right after the first
krealloc() succeeds, so the pointer always refers to a valid allocation
that meson_card_clean_references() can walk and free. krealloc() with
__GFP_ZERO zero-initializes the added entries, so walking them on the
error path is safe. With both failure paths reduced to a plain return,
drop the goto labels and the error message.
Published: 2026-09-17
Score: 7.4 High
EPSS: < 1% Very Low
KEV: No
Impact: Use‑after‑free and double free in kernel
Action: Immediate Patch
AI Analysis

Impact

The flaw causes a use‑after‑free and double free in the Linux ASoC meson driver during dynamic array reallocation. When the first krealloc() succeeds and the second fails, the driver frees a block that has already been freed, leaving card->dai_link pointing to an invalid block. The error path then dereferences that stale pointer, corrupting kernel memory. Based on the description, it is inferred that an attacker who can force this allocation sequence may crash the kernel or inject code, potentially escalating privileges.

Affected Systems

Any Linux kernel that includes the meson audio driver without the recent patch, regardless of distribution, is affected. No specific release lines are listed, so all unpatched kernel versions that contain the vulnerable code are vulnerable.

Risk and Exploitability

The CVSS score of 7.4 indicates a serious risk. The EPSS score of <1% shows that the likelihood of exploitation is very low at present, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the flaw could be exploitable locally by an attacker able to trigger the reallocation failure path, but no public exploit is known.

Generated by OpenCVE AI on September 19, 2026 at 23:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a patched release that incorporates the commit correcting the reallocation logic
  • Rebuild affected kernel modules to ensure the updated code is loaded
  • Reboot the system after the kernel update to finish applying the changes

Generated by OpenCVE AI on September 19, 2026 at 23:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Sat, 19 Sep 2026 17:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-415
CWE-416

Sat, 19 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-415
CWE-416

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: ASoC: meson: Keep link pointers valid on realloc failure meson_card_reallocate_links() grows the DAI link and private data arrays with two consecutive krealloc() calls and updates the owner pointers only after both calls have succeeded. A successful krealloc() may move the data: it frees the old block and returns a new one. When that happens for the link array and the second krealloc() then fails, card->dai_link still points to the block that krealloc() already freed, and the error path frees the new block too. The probe error path then calls meson_card_clean_references(), which dereferences card->dai_link and kfree()s it again, resulting in a use-after-free and a double free. Commit card->dai_link and card->num_links right after the first krealloc() succeeds, so the pointer always refers to a valid allocation that meson_card_clean_references() can walk and free. krealloc() with __GFP_ZERO zero-initializes the added entries, so walking them on the error path is safe. With both failure paths reduced to a plain return, drop the goto labels and the error message.
Title ASoC: meson: Keep link pointers valid on realloc failure
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:55:42.991Z

Reserved: 2026-09-17T15:57:05.657Z

Link: CVE-2026-93039

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:56.977

Modified: 2026-09-18T18:18:18.750

Link: CVE-2026-93039

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T23:30:13Z

Weaknesses