Use-after-free in Linux kernel - CVE-2026-64481
Published: July 27, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free in the cs35l41_hda firmware load work and ALSA control handling when a firmware load is requested and queued work executes after component unbind or device removal. A local user can trigger a firmware load request and remove the component or device before the queued work runs to cause a denial of service.
Exploitation requires firmware autostart to be disabled and can occur before DSP initialization.
Affected software
Debian Linux
linux (Debian package)
How to mitigate CVE-2026-64481
linux (Debian package) - update to 6.12.100-1