{"id":"AZL-106260","summary":"CVE-2026-98266 affecting package kernel 6.6.157.1-1","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: core: Fix potential UAF after asynchronous card release\n\nUsually a sound driver releases the resources assigned to the card via\nsnd_card_free(), and it synchronizes with the whole release procedure.\nHowever, when the card is released asynchronously via\nsnd_card_free_when_closed() like USB-audio driver, the situation is\nslightly different; although the snd_card_disconnect() call at the\ndisconnection guarantees that any newer accesses will be gated, the\nin-flight tasks might be still accessing to the underlying card-\u003edev\ndevice even after the disconnection, which would cause a\nuse-after-free in the end, as reported by fuzzers.\n\nFor addressing the bug above, this patch takes the refcount of\ncard-\u003edev at initialization of the card object, and releases at its\ndestructor.   This assures the availability of the card-\u003edev in its\nwhole lifecycle.","modified":"2026-10-07T14:16:59.829709776Z","published":"2026-10-06T09:18:15Z","upstream":["CVE-2026-98266"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-98266"}],"affected":[{"package":{"name":"kernel","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/kernel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"6.6.157.1-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-106260.json"}}],"schema_version":"1.9.0"}