CVE-2026-46049 Details
Description
In the Linux kernel, the following vulnerability has been resolved: ALSA: ctxfi: Add fallback to default RSR for S/PDIF spdif_passthru_playback_get_resources() uses atc->pll_rate as the RSR for the MSR calculation loop. However, pll_rate is only updated in atc_pll_init() and not in hw_pll_init(), so it remains 0 after the card init. When spdif_passthru_playback_setup() skips atc_pll_init() for 32000 Hz, (rsr * desc.msr) always becomes 0, causing the loop to spin indefinitely. Add fallback to use atc->rsr when atc->pll_rate is 0. This reflects the hardware state, since hw_card_init() already configures the PLL to the default RSR.
A vulnerability in the Linux kernel's ALSA Context-Fusion driver can lead to an infinite loop during S/PDIF playback. The issue arises because the playback resource function relies on a rate value that is not properly initialized after the sound card is activated. Specifically, the function 'spdif_passthru_playback_get_resources' uses a variable that should reflect the current hardware state, but it remains at zero due to a skipped initialization step for certain playback frequencies. As a result, the calculation loop can become stuck indefinitely, disrupting normal audio processing.
Users can update to the latest version of the Linux kernel where this vulnerability has been addressed. The official Linux kernel Git repository contains the patched version.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/09496158f6ebba8830593f8972035c02f97124c1 | kernel.org | Patch |
| https://git.kernel.org/stable/c/25ded535ee261161bcf19dafd525c542e606559d | kernel.org | Patch |
| https://git.kernel.org/stable/c/30f9494c6f2b53a78822cfb653ffbb1d092d44c8 | kernel.org | Patch |
| https://git.kernel.org/stable/c/615b7a5e5d8be68d52f262579906f7e015ba4606 | kernel.org | Patch |
| https://git.kernel.org/stable/c/7d61662197ecdc458e33e475b6ada7f6da61d364 | kernel.org | Patch |
| https://git.kernel.org/stable/c/95b1ee8442cabbde83b2848e7c6100df90f3a00d | kernel.org | Patch |
| https://git.kernel.org/stable/c/d0b53842211f73a10ea174100a213f7fa14b9f33 | kernel.org | Patch |
| https://git.kernel.org/stable/c/dfc00979ff00d9dfdfa1df32144a272ee2728102 | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 2.6.31, < 5.10.258 >= 5.11, < 5.15.209 >= 5.16, < 6.1.175 >= 6.2, < 6.6.140 >= 6.7, < 6.12.86 >= 6.13, < 6.18.27 >= 6.19, < 7.0.4 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | kernel.org |
| Jun 16, 2026 | Initial Analysis | [email protected] |
| Jun 1, 2026 | CVE Modified | kernel.org |
| May 27, 2026 | New CVE Received | kernel.org |