Executive brief
A resource leak was identified in the Linux kernel's audio driver for STMicroelectronics (sti) devices. When the audio player is initialized, certain memory objects are created but never properly released, which could lead to a gradual depletion of system resources if the driver is repeatedly loaded and unloaded. This primarily affects system stability and long-term availability rather than direct data security.
Technical details
A memory leak vulnerability exists in the Linux kernel's Advanced Linux Sound Architecture (ALSA) SoC (ASoC) driver for STMicroelectronics (sti) platforms, specifically within 'sound/soc/sti/uniperif_player.c'. The 'regmap_field' objects allocated during the 'uni_player_parse_dt_audio_glue' phase are not explicitly freed, leading to a leak when the driver is removed. The fix involves migrating from 'regmap_field_alloc()' to the managed 'devm_regmap_field_alloc()' function, which ensures the allocation lifetime is tied to the device itself. This is a local resource management issue with minimal security impact beyond potential denial-of-service through resource exhaustion.
Affected products
- Linux Linux Kernel 4.3 to 6.6.141
Timeline
- 2026-06-24: disclosed: Initial publication of the CVE record.
- 2026-06-24: advisory: NVD publication date.
References
- https://git.kernel.org/stable/c/002a5f925d42eca8ad547e55a4ae22714cfe9dec
- https://git.kernel.org/stable/c/1696fad8b259a2d46e51cd6e17e4bcdbe02279fa
- https://git.kernel.org/stable/c/43b67761d486d719128e164536e58de5a81dff9b
- https://git.kernel.org/stable/c/4b8dba4527727623a97948aff9f0969a14c203a9
- https://git.kernel.org/stable/c/7422a11a753daacbc2409513cf65e1de0d17c291
- https://git.kernel.org/stable/c/9641071e3a8e0bc664477a0e54db5f9815f0fb79
- https://git.kernel.org/stable/c/a3f3c332882c98ae7553af372191116d1384ca52