Junglewise Threat Intelligence

CVE-2026-64491: Linux Kernel use-after-free in ALSA Tascam US-144MKII driver

CVE-2026-64491 · Severity: info · Published 2026-07-25

Technologies: Linux. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's support for Tascam US-144MKII USB audio interfaces. When the device is disconnected, a race condition can occur that allows the system to attempt to use memory that has already been freed. This could lead to a system crash or unpredictable behavior when the audio hardware is unplugged.

Technical details

A use-after-free (UAF) vulnerability exists in sound/usb/usx2y/us144mkii.c within the tascam_disconnect() function. The root cause is an incorrect sequence of operations where capture and MIDI work items are cancelled before the associated anchored URBs are killed. Because these URBs can self-resubmit, a URB completing in the window between cancellation and killing can re-arm the work handler. When the device structure is subsequently freed by snd_card_free(), the re-armed work handler executes on freed memory. The fix reorders the operations to kill anchored URBs before cancelling the work queues.

Affected products

  • Linux Linux 6.18, 7.1.4, 7.2-rc2

Timeline

  • 2026-07-01: patched: Initial fix committed to mainline kernel
  • 2026-07-25: disclosed: CVE published

References