Junglewise Threat Intelligence

CVE-2026-43095: Linux Kernel ASoC SDCA use-after-free in IRQ cleanup

CVE-2026-43095 · Severity: medium · CVSS 5.5 · Published 2026-05-06

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's sound subsystem could allow a local user to cause a system crash. The issue occurs when a sound card is disconnected or shut down, but the system fails to properly clean up background tasks (interrupts). This leads to the system trying to access memory that is no longer available, resulting in a denial-of-service.

Technical details

A use-after-free or null pointer dereference vulnerability exists in the ASoC (ALSA System on Chip) SDCA (SoundWire Device Class Audio) driver. IRQs were previously requested using devm_request_threaded_irq() during component probe, which caused them to persist after the sound card was torn down. Because IRQ handlers maintained references to the card and kcontrols that were freed during teardown, subsequent IRQ triggers resulted in kernel crashes. The fix involves moving away from managed (devm) IRQ allocation to manual registration and explicit cleanup during the component removal phase.

Affected products

  • Linux Linux Kernel 6.17.1 to 6.19.14

Timeline

  • 2026-03-16: patched: Initial patch authored by Charles Keepax
  • 2026-05-06: disclosed: CVE published

References