CVE-2026-89736 is a vulnerability in Linux Kernel
Published on September 11, 2026
usb: gadget: u_audio: Fix use-after-free on sound card disconnect
In the Linux kernel, the following vulnerability has been resolved:
usb: gadget: u_audio: Fix use-after-free on sound card disconnect
g_audio_cleanup() invokes snd_card_free_when_closed() to initiate sound
card teardown and immediately frees the underlying struct snd_uac_chip
context. However, snd_card_free_when_closed() returns asynchronously
while ALSA control elements (kctls) remain open in userspace.
When userspace control applications access or close these open file
descriptors, kctl callbacks attempt to dereference kctl->private_data
pointing to &uac->c_prm or &uac->p_prm within the freed uac structure,
resulting in a use-after-free (UAF) memory corruption.
Fix this issue by deferring the destruction of struct snd_uac_chip until
all references to the ALSA sound card are released. Register a custom
card->private_free callback (u_audio_card_free) during g_audio_setup()
that frees uac and its associated playback/capture request and ring
buffers only when the sound card reference count drops to zero.
Products Associated with CVE-2026-89736
Want to know whenever a new CVE is published for Linux Kernel? stack.watch will email you.
Affected Versions
Linux:- Version 6c67ed9ad9b83e453e808f9b31a931a20a25629b and below c74ff0b1a0fca53d3ac185873c87d6a719b30a47 is affected.
- Version 6c67ed9ad9b83e453e808f9b31a931a20a25629b and below 4e747c864a88537e18b1ffc19a1954c9686bb8e1 is affected.
- Version 6c67ed9ad9b83e453e808f9b31a931a20a25629b and below 79a92896e2bb9471550c56fc23d8d93592f04c27 is affected.
- Version 6c67ed9ad9b83e453e808f9b31a931a20a25629b and below 858965947081d10d41d9a1010a540d3d5eea958b is affected.
- Version 3e016ef2e72da93a2ea7afbb45de1b481b44d761 is affected.
- Version 3256e152b645fc1e788ba44c2d8ced690113e3e6 is affected.
- Version 0eda2004f38d95ef5715d62be884cd344260535b is affected.
- Version 33f341c1fc60e172a3515c51bdabee11e83d1ee9 is affected.
- Version b131989797f7287d7fdadb2bababc05a15d44750 is affected.
- Version 3bc7324e4911351e39c54a62e6ca46321cb10faf is affected.
- Version 43ca70753dfffd517d2af126da28690f8f615605 is affected.
- Version 4.14.312 and below 4.15 is affected.
- Version 4.19.280 and below 4.20 is affected.
- Version 5.4.240 and below 5.5 is affected.
- Version 5.10.177 and below 5.11 is affected.
- Version 5.15.105 and below 5.16 is affected.
- Version 6.1.22 and below 6.2 is affected.
- Version 6.2.9 and below 6.3 is affected.
- Version 6.3 is affected.
- Before 6.3 is unaffected.
- Version 6.12.109, <= 6.12.* is unaffected.
- Version 6.18.50, <= 6.18.* is unaffected.
- Version 7.2.4, <= 7.2.* is unaffected.
- Version 7.3-rc1, <= * is unaffected.