Use-after-free in Linux kernel - CVE-2026-90198
Published: September 19, 2026
Vulnerability details
The vulnerability allows a local user to trigger a use-after-free.
The vulnerability exists due to a use-after-free in snd_card_do_free() when a managed sound card is unbound while an application retains an open file descriptor. A local user can close the open file descriptor while the managed sound card is being unbound to trigger a use-after-free.
Affected software
How to mitigate CVE-2026-90198
External References
- https://git.kernel.org/stable/c/03c5dabc8f16bc212a5b26d2425c03a55e55a86d
- https://git.kernel.org/stable/c/09b27dd01b98480334c10bf6fb8d41d5fb063a4b
- https://git.kernel.org/stable/c/5ae1a690c522fea2900ff56c8c2ace7b059f5e04
- https://git.kernel.org/stable/c/6da22efb5cf490b06ffbca32b10fc8af7654fee0
- https://git.kernel.org/stable/c/7d9b5e86775fa97a487da08b9aa76e1674bf8868
- https://git.kernel.org/stable/c/a561012868ae37c28f61fdf658bf6f251bc0e8e8
- https://git.kernel.org/stable/c/d3d67f680dbc23a5e5e3d3ecfdbf700465809877