From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id D1D5F3CD8BF for ; Fri, 4 Sep 2026 16:52:13 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788540736; cv=none; b=d6XhM3jBSkoVamtkh9qNIIZim+04dBMqJfR7BmSpsj4bDRGbTN3FSgt/QokYxKayjFzcAIq+D2jTLD3RAQlCMGuDcjNiik0t//rP/eEzXVuOYXgb+5uDvRn9R2TaP0toNdYejt4Ly8yq8BDMmoEfHG7zBrfIVMttyGslwFXHBFM= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788540736; c=relaxed/simple; bh=eIM2hC7JtZNukw9BGorrkuJx2T69rWVORhl7kyHNfQ8=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=M51eeMmQR5ZmPbHLbkrH80RBBrX0zl0mj/KErvxOWpUbWl+PKvkvCMcXUjE5KBb0T9Q/DanNUPhkdOnptH2HnvbIphPfS3AJp76FRSrOHOkkyqy229L0aV+gQlU3NdPkUSzNy8LPwU3YkA7rIXg5Hd3qXy9A7MVGrtaGDW9hBoc= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=xETylUxM; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="xETylUxM" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 346DA1F00A3D; Fri, 4 Sep 2026 16:52:08 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1788540733; bh=tnp637f+zyISrUfFQ9fG0kyAxrrRDqa9k5Fxf5cx59s=; h=From:To:Cc:Subject:Date:Reply-To; b=xETylUxM1hnzN0jp2eebl/2w6Nrip87JAzccJ26fDiZRFo6am9COTWdCvb7xPWBHa F0eddbk25P5qsMzyVh9h1UBaioXi1Ljr6QmQcmMAn+BEbXDDOI6YYIzsR5jbA8PYht l1rjWtzOiqZDg3NO/PVzty9VifZBotEjakVNN12I= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2026-80872: ALSA: hda/tas2781: Cancel async firmware request at unbind Date: Fri, 4 Sep 2026 18:46:39 +0200 Message-ID: <2026090435-CVE-2026-80872-58a7@gregkh> X-Mailer: git-send-email 2.55.0 Reply-To: , Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=2765; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=lBzh4Av9rP8cnYnMvglGl5ZWvjjEv0Dzf0bskomPS3g=; b=owGbwMvMwCRo6H6F97bub03G02pJDFmzvr5+rf1a7LvNQdvl5w95KW1ReXhSsyHk6InayfwCZ xc9vaAY0xHLwiDIxCArpsjyZRvP0f0VhxS9DG1Pw8xhZQIZwsDFKQAT0Z/EsOBmYLX5jshU1ltX zH75mdl2iB53/8aw4Mw9zbCCrF3bbWJXNNX8371NwfrOHgA= X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit From: Greg Kroah-Hartman Description =========== In the Linux kernel, the following vulnerability has been resolved: ALSA: hda/tas2781: Cancel async firmware request at unbind TAS2781 HDA I2C and SPI queue RCA firmware loading from component bind with request_firmware_nowait(). The firmware loader keeps the callback module pinned and holds a device reference, but the callback still uses driver-private HDA state. Component unbind removes controls and DSP state immediately. Later device removal tears down the TAS2781 private data, including codec_lock. If the async firmware callback runs after unbind has started, it can operate on state that is being torn down. Cancel or synchronize the async firmware request before removing controls and DSP state. A queued callback is cancelled, and an already-running callback is allowed to finish before unbind continues. The Linux kernel CVE team has assigned CVE-2026-80872 to this issue. Affected and fixed versions =========================== Issue introduced in 6.6 with commit 5be27f1e3ec98975c18a91e220d4847d0dec9671 and fixed in 6.18.40 with commit f8272331da877eec8fe8e89a1e98e6a710e12490 Issue introduced in 6.6 with commit 5be27f1e3ec98975c18a91e220d4847d0dec9671 and fixed in 7.1.5 with commit da9e3be9cf31d7138d23e9e2f7ba1c102ef09f07 Issue introduced in 6.6 with commit 5be27f1e3ec98975c18a91e220d4847d0dec9671 and fixed in 7.2 with commit 5367e2ad14f0ae9350a7aaf2e77c87de39a43ae9 Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-80872 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: sound/hda/codecs/side-codecs/tas2781_hda_i2c.c sound/hda/codecs/side-codecs/tas2781_hda_spi.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/f8272331da877eec8fe8e89a1e98e6a710e12490 https://git.kernel.org/stable/c/da9e3be9cf31d7138d23e9e2f7ba1c102ef09f07 https://git.kernel.org/stable/c/5367e2ad14f0ae9350a7aaf2e77c87de39a43ae9