{"id":"CVE-2026-43459","summary":"ASoC: soc-core: flush delayed work before removing DAIs and widgets","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: soc-core: flush delayed work before removing DAIs and widgets\n\nWhen a sound card is unbound while a PCM stream is open, a\nuse-after-free can occur in snd_soc_dapm_stream_event(), called from\nthe close_delayed_work workqueue handler.\n\nDuring unbind, snd_soc_unbind_card() flushes delayed work and then\ncalls soc_cleanup_card_resources(). Inside cleanup,\nsnd_card_disconnect_sync() releases all PCM file descriptors, and\nthe resulting PCM close path can call snd_soc_dapm_stream_stop()\nwhich schedules new delayed work with a pmdown_time timer delay.\nSince this happens after the flush in snd_soc_unbind_card(), the\nnew work is not caught. soc_remove_link_components() then frees\nDAPM widgets before this work fires, leading to the use-after-free.\n\nThe existing flush in soc_free_pcm_runtime() also cannot help as it\nruns after soc_remove_link_components() has already freed the widgets.\n\nAdd a flush in soc_cleanup_card_resources() after\nsnd_card_disconnect_sync() (after which no new PCM closes can\nschedule further delayed work) and before soc_remove_link_dais()\nand soc_remove_link_components() (which tear down the structures the\ndelayed work accesses).","modified":"2026-07-21T09:53:01.077561416Z","published":"2026-05-08T14:22:22.651Z","related":["SUSE-SU-2026:3130-1"],"database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/43xxx/CVE-2026-43459.json"},"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/231568afbc0cd25b8fb2a94ebf9738eabe1cf007"},{"type":"WEB","url":"https://git.kernel.org/stable/c/317a9298c54bb00319da73e5a7179f00e67fcbdf"},{"type":"WEB","url":"https://git.kernel.org/stable/c/3887e514978d28216246360b46a9cb534969eb5a"},{"type":"WEB","url":"https://git.kernel.org/stable/c/7d33e6140945482a07f8089ee86e13e02553ffdb"},{"type":"WEB","url":"https://git.kernel.org/stable/c/95bc5c225513fc3c4ce169563fb5e3929fbb938b"},{"type":"WEB","url":"https://git.kernel.org/stable/c/bf80a89da97285d9b877e0c6995e870d46b8025c"},{"type":"WEB","url":"https://git.kernel.org/stable/c/c054f0607c8bb1b1aa529bc109e4149298a1cccd"},{"type":"WEB","url":"https://git.kernel.org/stable/c/eab71e11ce2447c1e01809cbc11eab4234cf8dc8"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/43xxx/CVE-2026-43459.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-43459"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"e894efef9ac7c10b7727798dcc711cccf07569f9"},{"fixed":"bf80a89da97285d9b877e0c6995e870d46b8025c"},{"fixed":"3887e514978d28216246360b46a9cb534969eb5a"},{"fixed":"231568afbc0cd25b8fb2a94ebf9738eabe1cf007"},{"fixed":"317a9298c54bb00319da73e5a7179f00e67fcbdf"},{"fixed":"eab71e11ce2447c1e01809cbc11eab4234cf8dc8"},{"fixed":"7d33e6140945482a07f8089ee86e13e02553ffdb"},{"fixed":"c054f0607c8bb1b1aa529bc109e4149298a1cccd"},{"fixed":"95bc5c225513fc3c4ce169563fb5e3929fbb938b"}]}],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-43459.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.20.0"},{"fixed":"5.10.253"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.11.0"},{"fixed":"5.15.203"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.16.0"},{"fixed":"6.1.167"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.2.0"},{"fixed":"6.6.130"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.7.0"},{"fixed":"6.12.78"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.13.0"},{"fixed":"6.18.19"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.19.0"},{"fixed":"6.19.9"}]}],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-43459.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"}]}