Improper control of a resource through its lifetime in Linux kernel - CVE-2026-43095
Published: May 7, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper resource lifecycle management in sdca_irq_populate() IRQ handling when tearing down the sound card. A local user can trigger sound card teardown while IRQ handlers still hold references to the card and kcontrols to cause a denial of service.
The issue occurs because IRQs can persist after the sound card is removed, leading to crashes when stale references are used.