CVE-2026-23089 Details
Description
In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Fix use-after-free in snd_usb_mixer_free() When snd_usb_create_mixer() fails, snd_usb_mixer_free() frees mixer->id_elems but the controls already added to the card still reference the freed memory. Later when snd_card_register() runs, the OSS mixer layer calls their callbacks and hits a use-after-free read. Call trace: get_ctl_value+0x63f/0x820 sound/usb/mixer.c:411 get_min_max_with_quirks.isra.0+0x240/0x1f40 sound/usb/mixer.c:1241 mixer_ctl_feature_info+0x26b/0x490 sound/usb/mixer.c:1381 snd_mixer_oss_build_test+0x174/0x3a0 sound/core/oss/mixer_oss.c:887 ... snd_card_register+0x4ed/0x6d0 sound/core/init.c:923 usb_audio_probe+0x5ef/0x2a90 sound/usb/card.c:1025 Fix by calling snd_ctl_remove() for all mixer controls before freeing id_elems. We save the next pointer first because snd_ctl_remove() frees the current element.
A use-after-free vulnerability has been identified in the Linux kernel's ALSA USB-audio subsystem. When the function 'snd_usb_create_mixer()' fails, the subsequent call to 'snd_usb_mixer_free()' incorrectly frees the 'id_elems' memory. However, the mixer controls that were already added to the sound card still reference this freed memory. This discrepancy leads to a use-after-free read when 'snd_card_register()' is executed, as the OSS mixer layer attempts to access the callbacks of the affected controls. The vulnerability arises because the 'snd_usb_mixer_free()' function does not properly unregister the mixer controls before freeing the associated memory, creating a risk of accessing invalid memory locations.
The vulnerability has been fixed by modifying the 'snd_usb_mixer_free()' function to call 'snd_ctl_remove()' for all mixer controls before freeing the 'id_elems' memory. This change ensures that the controls are properly unregistered, preventing any references to freed memory.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 10, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/51b1aa6fe7dc87356ba58df06afb9677c9b841ea | kernel.org | Patch |
| https://git.kernel.org/stable/c/56fb6efd5d04caf6f14994d51ec85393b9a896c6 | kernel.org | Patch |
| https://git.kernel.org/stable/c/7009daeefa945973a530b2f605fe445fc03747af | kernel.org | Patch |
| https://git.kernel.org/stable/c/7bff0156d13f0ad9436e5178b979b063d59f572a | kernel.org | Patch |
| https://git.kernel.org/stable/c/930e69757b74c3ae083b0c3c7419bfe7f0edc7b2 | kernel.org | Patch |
| https://git.kernel.org/stable/c/dc1a5dd80af1ee1f29d8375b12dd7625f6294dad | kernel.org | Patch |
| https://git.kernel.org/stable/c/e6f103a22b08daf5df2f4aa158081840e5910963 | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-416 | Use After Free | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 2.6.13, < 5.10.249 >= 5.11, < 5.15.199 >= 5.16, < 6.1.162 >= 6.2, < 6.6.122 >= 6.7, < 6.12.68 >= 6.13, < 6.18.8 6.19 rc1 6.19 rc2 6.19 rc3 6.19 rc4 6.19 rc5 6.19 rc6 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | kernel.org |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 17, 2026 | Initial Analysis | [email protected] |
| Feb 6, 2026 | CVE Modified | kernel.org |
| Feb 4, 2026 | New CVE Received | kernel.org |