Use-after-free in Linux kernel - CVE-2026-80971
Published: September 12, 2026
Vulnerability details
The vulnerability allows an attacker with physical access to cause a use-after-free condition.
The vulnerability exists due to use-after-free in the ALSA bcd2000 driver's URB handling when a BCD2000 USB device is disconnected while a rawmidi substream remains open. An attacker with physical access can disconnect the device while the substream remains open to cause a use-after-free condition.