SB2026091766 - Double free in Linux kernel pci cobalt driver
Published: September 17, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Double free (CVE-ID: CVE-2026-89895)
CWE-ID: CWE-415 - Double Free
CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a double free in the cobalt ALSA initialization error cleanup path when initializing cobalt ALSA support. A local user can cause cobalt_alsa_init() to fail after snd_cobalt_card_create() to cause a denial of service.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/3a7d6b9c4cb5ac18cbd3f1c7f8c7b159c42ba0b1
- https://git.kernel.org/stable/c/42e00371f83c3fc7b99a36bf0229c74ad5d3c7d8
- https://git.kernel.org/stable/c/61dfa8ded5efc3a25d331fa9ce5cebb85531fe70
- https://git.kernel.org/stable/c/6cbc8a73b3464ebeccc49987b7233b6b087b8504
- https://git.kernel.org/stable/c/75bbf45e3a954e292ae26832d2df40ca2e3ee452
- https://git.kernel.org/stable/c/8c6610e230b9355cf7df5a338a0592c0f088c00b
- https://git.kernel.org/stable/c/cb1218da234ea15fa14d90e2d049d686874d7aa3
- https://git.kernel.org/stable/c/fe65028ee72a7e07e572b351891bd7a1f8917d33