CVE-2026-31581: ALSA: 6fire: fix use-after-free on disconnect
In the Linux kernel, the following vulnerability has been resolved:
ALSA: 6fire: fix use-after-free on disconnect
In usb6firechipabort(), the chip struct is allocated as the card's private data (via sndcardnew with sizeof(struct sfirechip)). When sndcardfreewhenclosed() is called and no file handles are open, the card and embedded chip are freed synchronously. The subsequent chip->card = NULL write then hits freed slab memory.
Call trace: usb6firechipabort sound/usb/6fire/chip.c:59 [inline] usb6firechipdisconnect+0x348/0x358 sound/usb/6fire/chip.c:182 usbunbindinterface+0x1a8/0x88c drivers/usb/core/driver.c:458 ... hubevent+0x1a04/0x4518 drivers/usb/core/hub.c:5953
Fix by moving the card lifecycle out of usb6firechipabort() and into usb6firechipdisconnect(). The card pointer is saved in a local before any teardown, sndcarddisconnect() is called first to prevent new opens, URBs are aborted while chip is still valid, and sndcardfreewhenclosed() is called last so chip is never accessed after the card may be freed.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Operational
Apply the code-level fix to the ALSA usb6fire driver as described: move the card lifecycle out of usb6fire_chip_abort() and into usb6fire_chip_disconnect(); save the card pointer in a local variable before teardown; call snd_card_disconnect() first to prevent new opens; abort URBs while the chip structure is still valid; and call snd_card_free_when_closed() last so the chip is never accessed after the card may be freed. Implement and deploy this patch to affected kernel builds containing sound/usb/6fire/chip.c.
Event History
Frequently Asked Questions
Which systems are exposed to this issue?
Systems using the Linux kernel ALSA usb6fire driver (sound/usb/6fire) are affected. The flaw is triggered in the USB 6fire device disconnect path.
What event triggers the vulnerable code path?
The issue occurs when the USB 6fire interface is disconnected. If no ALSA card file handles are open, snd_card_free_when_closed() can free the card and its embedded chip structure synchronously before a later write to chip->card.
Are active audio clients required for the use-after-free to occur?
No. The described use-after-free specifically arises when snd_card_free_when_closed() is called while no file handles are open, allowing immediate card teardown.
What does the fix change in the disconnect sequence?
The fix saves the card pointer before teardown, disconnects the card to block new opens, aborts URBs while the chip remains valid, and frees the card only after those operations complete. This prevents any access to the embedded chip after its card may have been freed.