CVE-2026-46004 Details
Description
In the Linux kernel, the following vulnerability has been resolved: ALSA: caiaq: Handle probe errors properly The probe procedure of setup_card() in caiaq driver doesn't treat the error cases gracefully, e.g. the error from snd_card_register() calls snd_card_free() but continues. This would lead to a UAF for the further calls like snd_usb_caiaq_control_init(), as Berk suggested in another patch in the link below. However, the problem is not only that; in general, this function drops the all error handlings (as it's a void function) although its caller can propagate an error to snd_probe(), which eventually calls snd_card_free() as a proper error path. That said, we should treat each error case in setup_card(), and just return the error code promptly, which is then handled later as a fatal error in snd_probe(). This patch achieves it by changing the setup_card() to return an error code. Also, the superfluous snd_card_free() call is removed, too. Note that card->private_free can be set still safely at returning an error. All called functions in card_free() have checks of the unassigned resources or NULL checks.
A vulnerability in the Linux kernel's ALSA Caiaq driver has been identified, where the probe procedure in the setup_card() function fails to manage errors properly. Specifically, while the snd_card_register() function's failure prompts a call to snd_card_free(), the process continues instead of halting. This oversight can lead to a use-after-free condition in subsequent function calls, such as snd_usb_caiaq_control_init(). Additionally, the setup_card() function, being a void function, neglects to handle errors appropriately, even though its caller can relay errors to snd_probe(), which would normally invoke snd_card_free() as part of the error management process. The vulnerability arises because the setup_card() function does not return error codes, leaving error handling to be managed later in the snd_probe() function. This patch addresses the issue by modifying setup_card() to return an error code, allowing for proper error propagation and handling. The unnecessary snd_card_free() call has also been removed, while still permitting the safe assignment of card->private_free in case of an error.
Users can upgrade to the patched version of the Linux kernel where this vulnerability has been addressed. The specific commit containing the fix can be downloaded from the Linux kernel stable tree.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/09616e25f502080ba684fc7fcf959d1376ab756d | kernel.org | Patch |
| https://git.kernel.org/stable/c/096dd8519cf2f768e9e14f224b627f7aaee1a9c5 | kernel.org | Patch |
| https://git.kernel.org/stable/c/28abd224db4a49560b452115bca3672a20e45b2f | kernel.org | Patch |
| https://git.kernel.org/stable/c/6251e3e256337a30160ef59ab1580dde4d1acd28 | kernel.org | Patch |
| https://git.kernel.org/stable/c/b956e48371f2ff72b76be9a829800ecec963bd45 | kernel.org | Patch |
| https://git.kernel.org/stable/c/da938aa9fc7826901921dcea225948ab21a97e45 | kernel.org | Patch |
| https://git.kernel.org/stable/c/e59ecd4ee3a450db6cb4e4ecaa3efdd593f80056 | kernel.org | Patch |
| https://git.kernel.org/stable/c/f537e3ad69609f6924a4db6b4a7f6561f5288bdd | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-416 | Use After Free | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 2.6.25, < 5.10.258 >= 5.11, < 5.15.209 >= 5.16, < 6.1.175 >= 6.2, < 6.6.140 >= 6.7, < 6.12.86 >= 6.13, < 6.18.27 >= 6.19, < 7.0.4 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | kernel.org |
| Jun 16, 2026 | Initial Analysis | [email protected] |
| Jun 1, 2026 | CVE Modified | kernel.org |
| May 27, 2026 | New CVE Received | kernel.org |