SB2026091827 - Improper control of a resource through its lifetime in Linux kernel soc codecs
Published: September 18, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Improper control of a resource through its lifetime (CVE-ID: CVE-2026-93185)
CWE-ID: CWE-664 - Improper control of a resource through its lifetime
CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local privileged user to cause active timer or work objects to remain after device removal.
The vulnerability exists due to improper cancellation of delayed work in rt700_sdw_remove() when removing an RT700 SoundWire codec after the SoundWire slave becomes unattached while jack work is pending. A local privileged user can cause the remove path to skip cancellation of pending jack work.
Practical reachability depends on SoundWire core remove ordering after an unattached status update.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/1bb23c9d68312e77cec81bdfb2cc385e2d2960f7
- https://git.kernel.org/stable/c/1e8fddab6cbe536dd02e61205e4b9bf97df6479b
- https://git.kernel.org/stable/c/45fcf435ffcc5f61a43bd9b19094dc52de6cbc05
- https://git.kernel.org/stable/c/612ccf42acd14bb2685fa60c3495ca13e63e8989
- https://git.kernel.org/stable/c/a47f087877bb2bc57c3ccb714fc49abf45d28e12
- https://git.kernel.org/stable/c/b81c2131dbb6fe04e27841bc719977c106177c61
- https://git.kernel.org/stable/c/f1e21b7b977f5ae2955ecf3ab144da2578a4fe00