Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-64491

Gravedad:
Pendiente de análisis
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
25/07/2026
Última modificación:
25/07/2026

Descripción

*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> ALSA: usx2y: us144mkii: fix work UAF on disconnect<br /> <br /> tascam_disconnect() cancels capture_work and midi_in_work before<br /> usb_kill_anchored_urbs() kills the capture/MIDI-in URBs. Those URBs<br /> self-resubmit, and their completion handlers reschedule the work.<br /> <br /> A URB that completes in the small window between cancel_work_sync() and<br /> usb_kill_anchored_urbs() therefore re-arms the work after its only<br /> cancel. Nothing cancels it again before snd_card_free() frees the<br /> card-private tascam structure, so the work handler then runs on freed<br /> memory.<br /> <br /> Kill the anchored URBs before cancelling the work; once the work is<br /> cancelled no remaining URB can complete to re-arm it.

Impacto