CVE-2026-72486
CVE CVE-2026-72486EUVD EUVD-2026-59385Published 2026-08-15T05:57:22.000ZLast changed 2026-08-17T05:15:36.000Z
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: mailbox: mtk-adsp: fix UAF during device teardown When the SOF audio driver fails to initialize (e.g. firmware boot timeout), its devres unwind frees the snd_sof_dev object that the mailbox client (mtk-adsp-ipc) reaches via chan->cl->rx_callback. The mtk-adsp-mailbox shutdown clears the mailbox command registers but leaves the IRQ line unmasked, so a late interrupt can still queue a threaded handler after mbox_free_channel() had cleared chan->cl, and mbox_chan_received_data() would then trigger UAF: BUG: KASAN: slab-use-after-free in sof_ipc3_validate_fw_version sof_ipc3_validate_fw_version sof_ipc3_do_rx_work sof_ipc3_rx_msg mt8196_dsp_handle_request mtk_adsp_ipc_recv mbox_chan_received_data mtk_adsp_mbox_isr irq_thread_fn Freed by task ...: kfree devres_release_all really_probe ... (sof-audio-of-mt8196 probe failure) The crash was observed roughly three seconds after the failed probe. disable_irq() in shutdown and enable_irq() in startup. disable_irq() also waits for any in-flight interrupts, so by the time mbox_free_channel() proceeds to clear chan->cl no rx_callback can run. In addition, request the IRQ with IRQF_NO_AUTOEN so it stays masked between probe and the first client bind — otherwise an early interrupt can crash on chan->cl == NULL in mbox_chan_received_data().
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux af2dfa96c52d042df5deb29fb6e32d3ff4d76a61 <e519c1d8c5efb5cd8d4c5bb3fe39b1bbb812bdb9; patch: 7.1.5; patch: 6.12.97; patch: 6.18.40; patch: 6.1.178; af2dfa96c52d042df5deb29fb6e32d3ff4d76a61 <7d881615fb6373f71fc628b3f00186aeca87a3d5; patch: 6.6.145; patch: 0; 5.18; af2dfa96c52d042df5deb29fb6e32d3ff4d76a61 <b6337a08a63eef8efcffe3c01d479badda6bbbdb; af2dfa96c52d042df5deb29fb6e32d3ff4d76a61 <25d6ea6c76e1b1b7c57337b2f8f1b6fc8d5c52bc; patch: 7.2; af2dfa96c52d042df5deb29fb6e32d3ff4d76a61 <fc6c3deb1d4c0adebf7dee0b8af4082af3f17690; af2dfa96c52d042df5deb29fb6e32d3ff4d76a61 <b57d1a40bc43258372fa1f4d39305e093947a262
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.