PatchSiren cyber security CVE debrief
CVE-2026-43459 Linux CVE debrief
CVE-2026-43459 is a Linux kernel use-after-free in the ASoC soc-core path that can occur during sound card unbind when a PCM stream is still open. The issue is reached through delayed work in the PCM close path and is rated HIGH by NVD with local access, low privileges, and user interaction required. The CVE was published on 2026-05-08 and later modified on 2026-05-21.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- HIGH 7.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-08
- Original CVE updated
- 2026-05-21
- Advisory published
- 2026-05-08
- Advisory updated
- 2026-05-21
Who should care
Linux administrators, OEMs, distro maintainers, and device vendors running affected Linux kernel branches that use the ALSA ASoC/PCM audio stack should prioritize this issue. Security teams should pay special attention where local users can interact with audio devices or trigger PCM open/close activity.
Technical summary
According to the CVE description, snd_soc_unbind_card() flushes delayed work and then calls soc_cleanup_card_resources(). During cleanup, snd_card_disconnect_sync() can release PCM file descriptors, and the PCM close path may schedule new delayed work via snd_soc_dapm_stream_stop() with a pmdown_time delay. Because that new work is scheduled after the earlier flush, it may fire after soc_remove_link_components() has already freed DAPM widgets, leading to a use-after-free in snd_soc_dapm_stream_event(). The described fix adds another flush in soc_cleanup_card_resources() after snd_card_disconnect_sync() and before DAI/widget teardown. NVD classifies the weakness as CWE-416.
Defensive priority
High for affected Linux kernel deployments; apply vendor or upstream fixes as soon as practical.
Recommended defensive actions
- Upgrade to a kernel version that includes the upstream fix for CVE-2026-43459.
- Apply the referenced stable kernel patches for the affected release branches if you cannot upgrade immediately.
- Prioritize systems on the affected Linux kernel version ranges listed by NVD, including the 4.20, 5.11, 5.16, 6.2, 6.7, 6.13, 6.19, and 7.0-rc branches where applicable.
- Review local-access exposure on systems where untrusted users can interact with ALSA/PCM audio devices.
- Track downstream vendor advisories and confirm that the fix is present in your distro or device kernel build.
Evidence notes
The supplied CVE description states that a use-after-free can occur in snd_soc_dapm_stream_event() when a sound card is unbound while a PCM stream is open. It explains that snd_card_disconnect_sync() can cause PCM close paths to schedule new delayed work after an initial flush in snd_soc_unbind_card(), and that soc_remove_link_components() can free DAPM widgets before that work runs. The description also states that the fix is to add a flush in soc_cleanup_card_resources() after snd_card_disconnect_sync() and before removing DAIs and widgets. NVD lists the weakness as CWE-416 and provides multiple kernel patch references, along with affected version ranges in its CPE criteria.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-43459 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-43459
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-43459 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-43459
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/231568afbc0cd25b8fb2a94ebf9738eabe1cf007
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/317a9298c54bb00319da73e5a7179f00e67fcbdf
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/3887e514978d28216246360b46a9cb534969eb5a
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/7d33e6140945482a07f8089ee86e13e02553ffdb
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/95bc5c225513fc3c4ce169563fb5e3929fbb938b
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/bf80a89da97285d9b877e0c6995e870d46b8025c
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/c054f0607c8bb1b1aa529bc109e4149298a1cccd
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.