PT-2026-39073 · Linux · Linux Kernel

CVE-2026-43412

·

Published

2026-05-08

·

Updated

2026-07-28

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the ASoC qcom qdsp6 component where incorrect removal ordering during ADSP stop and start operations leads to a kernel crash. Specifically, the q6apm-audio .remove callback unloads topology and removes PCM runtimes during ASoC teardown. This process deletes the RTDs containing the q6apm DAI components before their own removal pass occurs, leaving those components linked to the card and causing a NULL pointer dereference during the subsequent rebind.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-43412
SUSE-SU-2026:3130-1
SUSE-SU-2026:3166-1
USN-8567-1
USN-8574-1
USN-8574-2
USN-8574-3
USN-8595-1
USN-8595-2
USN-8595-3
USN-8596-1
USN-8606-1
USN-8607-1
USN-8608-1
USN-8609-1
USN-8619-1

Affected Products

Linux Kernel