SB2026091904 - Use-after-free in Linux kernel soc xilinx
Published: September 19, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Use-after-free (CVE-ID: CVE-2026-90214)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to trigger a use-after-free condition.
The vulnerability exists due to improper error handling in xlnx_formatter_pcm_open() in the ASoC Xilinx formatter PCM driver when handling errors during PCM stream initialization. A local user can open a PCM stream that encounters a constraint setup error to trigger a use-after-free condition.
ALSA does not invoke the close callback when opening a stream fails.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/3fd89a51b8cfe788df67f54b716b305dd45b8468
- https://git.kernel.org/stable/c/4e0ce77df7d9808926719d7950a07fbad14ea9ef
- https://git.kernel.org/stable/c/5e1a2d9fff57f3a2b1a0f54d128d64245a253004
- https://git.kernel.org/stable/c/8b30628dfc2b2fad3b55a9441776a226035045fa
- https://git.kernel.org/stable/c/8c38ae4a465691947977c25d10394da22a64a19f
- https://git.kernel.org/stable/c/9030aa4e14b704dc39ee208207cb65064020d857
- https://git.kernel.org/stable/c/b992511180e126150c6ad3580a6fd568c385f4c6
- https://git.kernel.org/stable/c/edf81b293cba1b00a5e71becf184414f6991a6ca