PT-2026-39073 · Linux · Linux Kernel

Published

2026-05-08

·

Updated

2026-05-21

·

CVE-2026-43412

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the ASoC qcom qdsp6 component where incorrect removal ordering during ADSP stop and start operations leads to a kernel crash. Specifically, the q6apm-audio .remove callback unloads topology and removes PCM runtimes during ASoC teardown. This process deletes the RTDs containing the q6apm DAI components before their own removal pass occurs, leaving those components linked to the card and causing a NULL pointer dereference during the subsequent rebind.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

CVE-2026-43412

Affected Products

Linux Kernel