Executive brief
A vulnerability exists in the Linux kernel's ALSA sound driver for 6fire USB devices. When a 6fire audio device is disconnected from the system, the kernel may attempt to access memory that has already been freed. This could lead to a system crash or potentially allow an attacker with local access to execute unauthorized code or escalate privileges.
Technical details
A use-after-free vulnerability exists in sound/usb/6fire/chip.c within the Linux kernel. The issue stems from usb6fire_chip_abort() where the 'chip' structure (allocated as private data for the sound card) is accessed after snd_card_free_when_closed() has already freed the card and its embedded chip data. This occurs specifically when a device is disconnected and no file handles are open, causing a synchronous free followed by a NULL pointer write to the freed memory. An attacker with local access or the ability to trigger USB disconnect events could exploit this to cause a kernel panic or achieve arbitrary code execution. The fix involves reordering the teardown sequence in usb6fire_chip_disconnect() to ensure the chip structure is not accessed after the card lifecycle is terminated.
Affected products
- Linux Linux Kernel up to 6.6.136, 6.12 to 6.12.83, 6.13 to 6.18.24, 6.19 to 6.19.14, 7.0 to 7.0.1
Timeline
- 2026-04-10: patched: Initial patch submitted by Berk Cem Goksel
- 2026-04-24: advisory: CVE-2026-31581 published
References
- https://git.kernel.org/stable/c/3dc20d1981d6a67d8184498a5da272942dde1e65
- https://git.kernel.org/stable/c/51f6532790b74ffdd6970bc848358a2838c1c185
- https://git.kernel.org/stable/c/af75b486f7e883e3422ece23c8d727e6815144a0
- https://git.kernel.org/stable/c/b9c826916fdce6419b94eb0cd8810fdac18c2386
- https://git.kernel.org/stable/c/ba88461f7653636c48321ca993006a74724c2f41
- https://git.kernel.org/stable/c/d21e8a2af4869b5890b34e081d5aeadc93e9cd5c
- https://git.kernel.org/stable/c/e247a0e01d15ed420f77ec5e2335721bf430a5b3