PT-2026-34933 · Linux · Linux Kernel

Published

2026-04-24

·

Updated

2026-05-06

·

CVE-2026-31581

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A use-after-free issue exists in the ALSA 6fire component. In the usb6fire chip abort() function, the chip structure is allocated as the card's private data. When snd card free when closed() is executed and no file handles are open, the card and the embedded chip are freed synchronously. This causes a subsequent write operation to chip->card = NULL to target freed slab memory.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Use After Free

Weakness Enumeration

Related Identifiers

CVE-2026-31581
ECHO-5B41-56D9-3E61
OPENSUSE-SU-2026:10703-1

Affected Products

Linux Kernel