Executive brief
A vulnerability was identified in the Linux kernel's cx88 driver, which supports certain video capture and tuner hardware. A flaw in how the system handles errors during audio setup can lead to a resource leak, where memory or hardware mappings are not properly released. This could allow a local user to cause a system crash or instability (denial of service) by repeatedly triggering these error conditions.
Technical details
A resource management vulnerability (CWE-772) exists in the cx88-alsa component of the Linux kernel. Specifically, in the `snd_cx88_hw_params()` function within `drivers/media/pci/cx88/cx88-alsa.c`, the code fails to call `cx88_alsa_dma_unmap()` when `cx88_risc_databuffer()` returns an error. This results in a failure to release DMA resources acquired by a previous call to `cx88_alsa_dma_map()`. A local attacker with sufficient privileges to interact with the media hardware could exploit this to exhaust system resources or cause a kernel panic. The issue has been resolved by adding the missing unmap call to the error path in multiple stable kernel branches.
Affected products
- Linux Linux Kernel 3.19 to 5.10.252, 5.11 to 5.15.202, 5.16 to 6.1.165, 6.2 to 6.6.128, 6.7 to 6.12.75, 6.13 to 6.18.16, 6.19 to 6.19.6
Timeline
- 2026-05-06: disclosed: CVE published by kernel.org
- 2026-05-11: advisory: NIST NVD advisory published
- 2026-01-13: patched: Initial patch committed to mainline kernel
References
- https://git.kernel.org/stable/c/10ab64f8efc2f479293dce929fde326c285fc96f
- https://git.kernel.org/stable/c/1ce8c2a8f050a23240553c8bae628ac623f9dbc1
- https://git.kernel.org/stable/c/24f3dabeb97bd0bec8c1c926c97e3eb6a8129225
- https://git.kernel.org/stable/c/3baefeeb7b85e1e34eebef399ffa312be7179e30
- https://git.kernel.org/stable/c/dbc527d980f7ba8559de38f8c1e4158c71a78915
- https://git.kernel.org/stable/c/dc911fccc6e08ef46a66b2a42a764252b001ee3c
- https://git.kernel.org/stable/c/e3fb15aadfc8643203bbdf97ace0396e4586fa64