CVE-2026-93039
CVE CVE-2026-93039EUVD EUVD-2026-82149Veröffentlicht 2026-09-17T16:10:32.000ZZuletzt geändert 2026-09-18T17:55:42.000ZCVSS 7.4
Was das Advisory beschreibt
In the Linux kernel, the following vulnerability has been resolved: ASoC: meson: Keep link pointers valid on realloc failure meson_card_reallocate_links() grows the DAI link and private data arrays with two consecutive krealloc() calls and updates the owner pointers only after both calls have succeeded. A successful krealloc() may move the data: it frees the old block and returns a new one. When that happens for the link array and the second krealloc() then fails, card->dai_link still points to the block that krealloc() already freed, and the error path frees the new block too. The probe error path then calls meson_card_clean_references(), which dereferences card->dai_link and kfree()s it again, resulting in a use-after-free and a double free. Commit card->dai_link and card->num_links right after the first krealloc() succeeds, so the pointer always refers to a valid allocation that meson_card_clean_references() can walk and free. krealloc() with __GFP_ZERO zero-initializes the added entries, so walking them on the error path is safe. With both failure paths reduced to a plain return, drop the goto labels and the error message.
Quelle: EUVD (ENISA), im Wortlaut der Meldung.
Produkte, die das Advisory nennt
Diese Angaben stammen aus der Meldung selbst, nicht aus einer Prüfung durch uns.
- Linux — Linux 7864a79f37b55769b817d5e6c5ae0ca4bfdba93b <1c1485343b7c1c39dab7ecb9cd16ba49fd0ce642; patch: 6.18.52; patch: 0; patch: 6.1.188; patch: 6.6.157; 7864a79f37b55769b817d5e6c5ae0ca4bfdba93b <de33afc57f24538186bccf4c4f6c65dd38634fd8; 4.19; 7864a79f37b55769b817d5e6c5ae0ca4bfdba93b <41e92e0caa1fe3df2efaca346bfcaeb7fb9826ab; patch: 7.2.6; patch: 6.12.110; patch: 7.3-rc1; 7864a79f37b55769b817d5e6c5ae0ca4bfdba93b <2aaa41cf974f83a6fb105422bac4e2f107150774; 7864a79f37b55769b817d5e6c5ae0ca4bfdba93b <8fec16898f184e5f8f8fdd09ff1ced2bd7ffc13d; patch: 5.10.270; 7864a79f37b55769b817d5e6c5ae0ca4bfdba93b <8db0a0fc84e80aa9924e0833aef6cc95df94e5a7; patch: 5.15.221; 7864a79f37b55769b817d5e6c5ae0ca4bfdba93b <0b30fbe6bf7cf6499b19dd886f466e7c9e820089; 7864a79f37b55769b817d5e6c5ae0ca4bfdba93b <5ed1b048527bebe4529eb6e01c34dcc5d97ba5fe
Die genannten Versionen sind die Angabe der Meldung. Patchlage vergleicht keine Versionsnummern und leitet aus ihnen keine Aussage ab — welche Version installiert ist, muss ein Mensch nachsehen.
Im Produktkatalog geführt
Für diese Produkte kann ein Bestand in Patchlage erfasst werden. Ein Advisory dazu erscheint am Morgen danach im Lagebericht.
- Linux — Linux
Betrifft das einen Ihrer Kundenbestände?
Diese Seite kann die Frage nicht beantworten — sie kennt Ihren Bestand nicht. Wer seine Umgebungen erfasst hat, bekommt die Antwort am Morgen nach der Veröffentlichung, zusammen mit einem Absatz, den er unverändert an den Kunden weitergeben kann.
28 Tage testenPatchlage meldet Treffer und Verdachtsfälle. Zu allem anderen sagt dieses System nichts — weder diese Seite noch der Lagebericht behauptet je, dass ein Bestand sicher ist.