Junglewise Threat Intelligence

CVE-2026-31581: Linux Kernel ALSA 6fire use-after-free on disconnect

CVE-2026-31581 · Severity: high · CVSS 7.8 · Published 2026-04-24

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability exists in the Linux kernel's ALSA sound driver for 6fire USB devices. When a 6fire audio device is disconnected from the system, the kernel may attempt to access memory that has already been freed. This could lead to a system crash or potentially allow an attacker with local access to execute unauthorized code or escalate privileges.

Technical details

A use-after-free vulnerability exists in sound/usb/6fire/chip.c within the Linux kernel. The issue stems from usb6fire_chip_abort() where the 'chip' structure (allocated as private data for the sound card) is accessed after snd_card_free_when_closed() has already freed the card and its embedded chip data. This occurs specifically when a device is disconnected and no file handles are open, causing a synchronous free followed by a NULL pointer write to the freed memory. An attacker with local access or the ability to trigger USB disconnect events could exploit this to cause a kernel panic or achieve arbitrary code execution. The fix involves reordering the teardown sequence in usb6fire_chip_disconnect() to ensure the chip structure is not accessed after the card lifecycle is terminated.

Affected products

  • Linux Linux Kernel up to 6.6.136, 6.12 to 6.12.83, 6.13 to 6.18.24, 6.19 to 6.19.14, 7.0 to 7.0.1

Timeline

  • 2026-04-10: patched: Initial patch submitted by Berk Cem Goksel
  • 2026-04-24: advisory: CVE-2026-31581 published

References

Related threats