* CVE-2026-80872: ALSA: hda/tas2781: Cancel async firmware request at unbind
@ 2026-09-04 16:46 Greg Kroah-Hartman
0 siblings, 0 replies; only message in thread
From: Greg Kroah-Hartman @ 2026-09-04 16:46 UTC (permalink / raw)
To: linux-cve-announce; +Cc: Greg Kroah-Hartman
From: Greg Kroah-Hartman <gregkh@kernel.org>
Description
===========
In the Linux kernel, the following vulnerability has been resolved:
ALSA: hda/tas2781: Cancel async firmware request at unbind
TAS2781 HDA I2C and SPI queue RCA firmware loading from component
bind with request_firmware_nowait(). The firmware loader keeps the
callback module pinned and holds a device reference, but the callback
still uses driver-private HDA state.
Component unbind removes controls and DSP state immediately. Later
device removal tears down the TAS2781 private data, including
codec_lock. If the async firmware callback runs after unbind has
started, it can operate on state that is being torn down.
Cancel or synchronize the async firmware request before removing
controls and DSP state. A queued callback is cancelled, and an
already-running callback is allowed to finish before unbind continues.
The Linux kernel CVE team has assigned CVE-2026-80872 to this issue.
Affected and fixed versions
===========================
Issue introduced in 6.6 with commit 5be27f1e3ec98975c18a91e220d4847d0dec9671 and fixed in 6.18.40 with commit f8272331da877eec8fe8e89a1e98e6a710e12490
Issue introduced in 6.6 with commit 5be27f1e3ec98975c18a91e220d4847d0dec9671 and fixed in 7.1.5 with commit da9e3be9cf31d7138d23e9e2f7ba1c102ef09f07
Issue introduced in 6.6 with commit 5be27f1e3ec98975c18a91e220d4847d0dec9671 and fixed in 7.2 with commit 5367e2ad14f0ae9350a7aaf2e77c87de39a43ae9
Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.
Unaffected versions might change over time as fixes are backported to
older supported kernel versions. The official CVE entry at
https://cve.org/CVERecord/?id=CVE-2026-80872
will be updated if fixes are backported, please check that for the most
up to date information about this issue.
Affected files
==============
The file(s) affected by this issue are:
sound/hda/codecs/side-codecs/tas2781_hda_i2c.c
sound/hda/codecs/side-codecs/tas2781_hda_spi.c
Mitigation
==========
The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes. Individual
changes are never tested alone, but rather are part of a larger kernel
release. Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all. If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
https://git.kernel.org/stable/c/f8272331da877eec8fe8e89a1e98e6a710e12490
https://git.kernel.org/stable/c/da9e3be9cf31d7138d23e9e2f7ba1c102ef09f07
https://git.kernel.org/stable/c/5367e2ad14f0ae9350a7aaf2e77c87de39a43ae9
^ permalink raw reply [flat|nested] only message in thread
only message in thread, other threads:[~2026-09-04 16:52 UTC | newest]
Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-04 16:46 CVE-2026-80872: ALSA: hda/tas2781: Cancel async firmware request at unbind Greg Kroah-Hartman
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.