Description
In the Linux kernel, the following vulnerability has been resolved:

ASoC: rt700-sdw: always drain jack work on remove

rt700_sdw_remove() drains jack_detect_work and jack_btn_check_work only
when rt700->hw_init is true. That state bit is cleared by
rt700_update_status() when the SoundWire slave becomes UNATTACHED, but a
jack work item can already have been queued by rt700_interrupt_callback()
or rt700_jack_init() while the device was initialized.

Do not use hw_init as the remove-time guard for draining these work
objects. The delayed works are initialized during rt700_init(), so remove
can cancel them unconditionally and pair the object lifetime with the
codec-private data lifetime instead of a mutable hardware state bit.

This issue was found by our static analysis tool and then confirmed by
manual review of the SoundWire status, interrupt and remove paths. The
remove path should drain work based on whether the work object exists, not
on a runtime hardware state bit that can change after the work was queued.

A QEMU PoC queued jack_detect_work, simulated SDW_SLAVE_UNATTACHED, and
then entered remove. DEBUG_OBJECTS reported an active timer/work object
associated with the rt700 jack work path after remove skipped the cancel.

This is sent as an RFC because the practical trigger depends on SoundWire
core remove ordering after an UNATTACHED status update. If remove cannot
run after hw_init has been cleared while jack work is still pending, this
is a defensive lifecycle cleanup rather than a reachable race on current
systems.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Use After Free; potential kernel panic on device removal
Action: Apply Patch
AI Analysis

Impact

The bug in the Linux ASoC rt700-sdw driver allows queued work functions (jack_detect_work and jack_btn_check_work) to remain pending during a device removal sequence when the hardware initialization flag is cleared too early. If the device enters the UNATTACHED state while work is queued, the removal path may skip draining these work objects, causing them to execute after the codec data has been freed. The inferred use‑after‑free condition suggests the possibility of a kernel crash, leading to system instability or denial of service.

Affected Systems

The flaw affects the Linux kernel, specifically the rt700-sdw component of the Advanced Linux Sound Architecture subsystem. Any kernel version that includes the unpatched rt700 driver is susceptible. The CNA identifies the product as Linux, Linux, with no specific version range provided.

Risk and Exploitability

The EPSS score is reported to be less than 1 % and the vulnerability is not listed in the CISA KEV catalog, indicating a low probability of known exploitation. However, the flaw is a local kernel bug that can cause a crash if an attacker can trigger a device removal while the use‑after‑free condition is pending. The inference that this can lead to a kernel crash is derived from the description. It would require privileged or local access to the affected hardware to manipulate the removal sequence; thus the attack vector is local. The intrinsic severity is high due to the potential for a full kernel panic, but realistic exploitation likelihood remains low given the required preparation.

Generated by OpenCVE AI on September 19, 2026 at 08:57 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that includes the rt700‑sdw fix which drains pending work unconditionally during device removal
  • If a newer kernel is not available, apply a local patch to the rt700_sdw_remove function that removes the hw_init guard and always calls cancel_work_sync on jack_detect_work and jack_btn_check_work
  • Rebuild the kernel with the patched source or apply the patch from the provided Git references before rebooting

Generated by OpenCVE AI on September 19, 2026 at 08:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 09:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: ASoC: rt700-sdw: always drain jack work on remove rt700_sdw_remove() drains jack_detect_work and jack_btn_check_work only when rt700->hw_init is true. That state bit is cleared by rt700_update_status() when the SoundWire slave becomes UNATTACHED, but a jack work item can already have been queued by rt700_interrupt_callback() or rt700_jack_init() while the device was initialized. Do not use hw_init as the remove-time guard for draining these work objects. The delayed works are initialized during rt700_init(), so remove can cancel them unconditionally and pair the object lifetime with the codec-private data lifetime instead of a mutable hardware state bit. This issue was found by our static analysis tool and then confirmed by manual review of the SoundWire status, interrupt and remove paths. The remove path should drain work based on whether the work object exists, not on a runtime hardware state bit that can change after the work was queued. A QEMU PoC queued jack_detect_work, simulated SDW_SLAVE_UNATTACHED, and then entered remove. DEBUG_OBJECTS reported an active timer/work object associated with the rt700 jack work path after remove skipped the cancel. This is sent as an RFC because the practical trigger depends on SoundWire core remove ordering after an UNATTACHED status update. If remove cannot run after hw_init has been cleared while jack work is still pending, this is a defensive lifecycle cleanup rather than a reachable race on current systems.
Title ASoC: rt700-sdw: always drain jack work on remove
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:12:11.454Z

Reserved: 2026-09-17T16:02:15.091Z

Link: CVE-2026-93185

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:18:14.547

Modified: 2026-09-17T17:18:14.547

Link: CVE-2026-93185

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T07:15:16Z

Weaknesses