PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-43459 Linux CVE debrief

CVE-2026-43459 is a Linux kernel use-after-free in the ASoC soc-core path that can occur during sound card unbind when a PCM stream is still open. The issue is reached through delayed work in the PCM close path and is rated HIGH by NVD with local access, low privileges, and user interaction required. The CVE was published on 2026-05-08 and later modified on 2026-05-21.

Vendor
Linux
Product
Unknown
CVSS
HIGH 7.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-08
Original CVE updated
2026-05-21
Advisory published
2026-05-08
Advisory updated
2026-05-21

Who should care

Linux administrators, OEMs, distro maintainers, and device vendors running affected Linux kernel branches that use the ALSA ASoC/PCM audio stack should prioritize this issue. Security teams should pay special attention where local users can interact with audio devices or trigger PCM open/close activity.

Technical summary

According to the CVE description, snd_soc_unbind_card() flushes delayed work and then calls soc_cleanup_card_resources(). During cleanup, snd_card_disconnect_sync() can release PCM file descriptors, and the PCM close path may schedule new delayed work via snd_soc_dapm_stream_stop() with a pmdown_time delay. Because that new work is scheduled after the earlier flush, it may fire after soc_remove_link_components() has already freed DAPM widgets, leading to a use-after-free in snd_soc_dapm_stream_event(). The described fix adds another flush in soc_cleanup_card_resources() after snd_card_disconnect_sync() and before DAI/widget teardown. NVD classifies the weakness as CWE-416.

Defensive priority

High for affected Linux kernel deployments; apply vendor or upstream fixes as soon as practical.

Recommended defensive actions

  • Upgrade to a kernel version that includes the upstream fix for CVE-2026-43459.
  • Apply the referenced stable kernel patches for the affected release branches if you cannot upgrade immediately.
  • Prioritize systems on the affected Linux kernel version ranges listed by NVD, including the 4.20, 5.11, 5.16, 6.2, 6.7, 6.13, 6.19, and 7.0-rc branches where applicable.
  • Review local-access exposure on systems where untrusted users can interact with ALSA/PCM audio devices.
  • Track downstream vendor advisories and confirm that the fix is present in your distro or device kernel build.

Evidence notes

The supplied CVE description states that a use-after-free can occur in snd_soc_dapm_stream_event() when a sound card is unbound while a PCM stream is open. It explains that snd_card_disconnect_sync() can cause PCM close paths to schedule new delayed work after an initial flush in snd_soc_unbind_card(), and that soc_remove_link_components() can free DAPM widgets before that work runs. The description also states that the fix is to add a flush in soc_cleanup_card_resources() after snd_card_disconnect_sync() and before removing DAIs and widgets. NVD lists the weakness as CWE-416 and provides multiple kernel patch references, along with affected version ranges in its CPE criteria.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-43459 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-43459

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-43459 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-43459

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/231568afbc0cd25b8fb2a94ebf9738eabe1cf007

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/317a9298c54bb00319da73e5a7179f00e67fcbdf

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/3887e514978d28216246360b46a9cb534969eb5a

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/7d33e6140945482a07f8089ee86e13e02553ffdb

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/95bc5c225513fc3c4ce169563fb5e3929fbb938b

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/bf80a89da97285d9b877e0c6995e870d46b8025c

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/c054f0607c8bb1b1aa529bc109e4149298a1cccd

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.