Improper control of a resource through its lifetime in Linux kernel - CVE-2026-93185
Published: September 18, 2026
Vulnerability details
The vulnerability allows a local privileged user to cause active timer or work objects to remain after device removal.
The vulnerability exists due to improper cancellation of delayed work in rt700_sdw_remove() when removing an RT700 SoundWire codec after the SoundWire slave becomes unattached while jack work is pending. A local privileged user can cause the remove path to skip cancellation of pending jack work.
Practical reachability depends on SoundWire core remove ordering after an unattached status update.
Affected software
How to mitigate CVE-2026-93185
External References
- https://git.kernel.org/stable/c/1bb23c9d68312e77cec81bdfb2cc385e2d2960f7
- https://git.kernel.org/stable/c/1e8fddab6cbe536dd02e61205e4b9bf97df6479b
- https://git.kernel.org/stable/c/45fcf435ffcc5f61a43bd9b19094dc52de6cbc05
- https://git.kernel.org/stable/c/612ccf42acd14bb2685fa60c3495ca13e63e8989
- https://git.kernel.org/stable/c/a47f087877bb2bc57c3ccb714fc49abf45d28e12
- https://git.kernel.org/stable/c/b81c2131dbb6fe04e27841bc719977c106177c61
- https://git.kernel.org/stable/c/f1e21b7b977f5ae2955ecf3ab144da2578a4fe00