Executive brief
A vulnerability was identified in the Linux kernel's audio driver for certain Cirrus Logic amplifiers. Under specific conditions where firmware is manually loaded, the system could attempt to access memory that has already been cleared during a device shutdown or removal. This could lead to a system crash or unpredictable behavior, potentially impacting the stability of devices using this specific audio hardware.
Technical details
A race condition exists in the sound/pci/hda/cs35l41_hda.c driver due to improper teardown of firmware load work. The driver creates ALSA controls that point to the cs35l41_hda object but fails to remove these controls during component unbind. If firmware_autostart is disabled, a firmware load request can queue work before the DSP is initialized. If the device is removed before this work executes, the worker thread may attempt to dereference invalid driver state (use-after-free). The fix involves tracking and removing controls on unbind and ensuring fw_load_work is cancelled during device removal.
Affected products
- Linux Linux Kernel 6.0 to 7.1.4
Timeline
- 2026-07-25: disclosed
- 2026-07-25: advisory