Race condition in Linux kernel - CVE-2026-89980
Published: September 16, 2026
Vulnerability details
The vulnerability allows a remote attacker to compromise confidentiality, integrity, and availability.
The vulnerability exists due to a race condition involving uninitialized locks in the ALSA Harmony driver when a pending interrupt is handled after IRQ registration and before lock initialization. A remote attacker can trigger a pending interrupt during device initialization to compromise confidentiality, integrity, and availability.
Affected software
How to mitigate CVE-2026-89980
External References
- https://git.kernel.org/stable/c/33abb7491e89285a41565670945293dda841afc4
- https://git.kernel.org/stable/c/7dc239edb6d58e01c9ec868565cc03e7adf91747
- https://git.kernel.org/stable/c/89992bda7dfbba7ded2ba4185730453c57fa65bc
- https://git.kernel.org/stable/c/9347588bbd6ad43a85e17046d9c117a41453c52a
- https://git.kernel.org/stable/c/9af6c9203583655cb7ed45e52e14101652b37547
- https://git.kernel.org/stable/c/cd209eb3136e002becbda232e399fa31a2276436
- https://git.kernel.org/stable/c/f86ff9238b0c8284909e073a681a60708b9f36ab