PT-2026-39073 · Linux · Linux Kernel
Published
2026-05-08
·
Updated
2026-05-21
·
CVE-2026-43412
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
An issue exists in the ASoC qcom qdsp6 component where incorrect removal ordering during ADSP stop and start operations leads to a kernel crash. Specifically, the
q6apm-audio .remove callback unloads topology and removes PCM runtimes during ASoC teardown. This process deletes the RTDs containing the q6apm DAI components before their own removal pass occurs, leaving those components linked to the card and causing a NULL pointer dereference during the subsequent rebind.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linux Kernel