SB2026091827 - Improper control of a resource through its lifetime in Linux kernel soc codecs



SB2026091827 - Improper control of a resource through its lifetime in Linux kernel soc codecs

Published: September 18, 2026

Security Bulletin ID SB2026091827
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Information disclosure

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Improper control of a resource through its lifetime (CVE-ID: CVE-2026-93185)

CWE-ID: CWE-664 - Improper control of a resource through its lifetime

CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local privileged user to cause active timer or work objects to remain after device removal.

The vulnerability exists due to improper cancellation of delayed work in rt700_sdw_remove() when removing an RT700 SoundWire codec after the SoundWire slave becomes unattached while jack work is pending. A local privileged user can cause the remove path to skip cancellation of pending jack work.

Practical reachability depends on SoundWire core remove ordering after an unattached status update.


Remediation

Install update from vendor's website.