Use-after-free in Linux kernel - CVE-2026-89736
Published: September 12, 2026
Vulnerability details
The vulnerability allows a local user to cause memory corruption.
The vulnerability exists due to use-after-free in the USB gadget u_audio sound card cleanup handling when accessing or closing open ALSA control file descriptors after sound card teardown is initiated. A local user can access or close open ALSA control file descriptors to cause memory corruption.
ALSA control callbacks can dereference private data associated with a freed sound card context.