PT-2026-34939 · Linux · Linux Kernel

Published

2026-04-24

·

Updated

2026-05-06

·

CVE-2026-31587

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the ASoC qcom q6apm component where dais are registered dynamically from ASoC topology using device managed APIs. When both the component and dynamic dais use managed versions, it can lead to incorrect free ordering, resulting in a slab-use-after-free condition where the dai is freed while the component still holds references to it. This was observed in the snd soc del component unlocked() function.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Use After Free

Weakness Enumeration

Related Identifiers

CVE-2026-31587
ECHO-4B61-DDB1-C9A7
OPENSUSE-SU-2026:10703-1

Affected Products

Linux Kernel