CVE-2026-31581: ALSA: 6fire: fix use-after-free on disconnect

Published Apr 24, 2026
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

ALSA: 6fire: fix use-after-free on disconnect

In usb6firechipabort(), the chip struct is allocated as the card's private data (via sndcardnew with sizeof(struct sfirechip)). When sndcardfreewhenclosed() is called and no file handles are open, the card and embedded chip are freed synchronously. The subsequent chip->card = NULL write then hits freed slab memory.

Call trace: usb6firechipabort sound/usb/6fire/chip.c:59 [inline] usb6firechipdisconnect+0x348/0x358 sound/usb/6fire/chip.c:182 usbunbindinterface+0x1a8/0x88c drivers/usb/core/driver.c:458 ... hubevent+0x1a04/0x4518 drivers/usb/core/hub.c:5953

Fix by moving the card lifecycle out of usb6firechipabort() and into usb6firechipdisconnect(). The card pointer is saved in a local before any teardown, sndcarddisconnect() is called first to prevent new opens, URBs are aborted while chip is still valid, and sndcardfreewhenclosed() is called last so chip is never accessed after the card may be freed.

Affected Software

6 affected components
Linux Linux kernel (ALSA usb6fire driver sound/usb/6fire)
Linux Linux kernel<6.6.136
Linux Linux kernel>=6.12<6.12.83
Linux Linux kernel>=6.13<6.18.24
Linux Linux kernel>=6.19<6.19.14
Linux Linux kernel>=7.0<7.0.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Operational

    Apply the code-level fix to the ALSA usb6fire driver as described: move the card lifecycle out of usb6fire_chip_abort() and into usb6fire_chip_disconnect(); save the card pointer in a local variable before teardown; call snd_card_disconnect() first to prevent new opens; abort URBs while the chip structure is still valid; and call snd_card_free_when_closed() last so the chip is never accessed after the card may be freed. Implement and deploy this patch to affected kernel builds containing sound/usb/6fire/chip.c.

Event History

Apr 24, 2026
CVE Published
via MITRE·02:42 PM
Data Sourced
via MITRE·02:42 PM
Description
Data Sourced
via Red Hat·03:03 PM
DescriptionSeverityAffected Software
Data Sourced
via NVD·03:16 PM
RemedyDescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

Which systems are exposed to this issue?

Systems using the Linux kernel ALSA usb6fire driver (sound/usb/6fire) are affected. The flaw is triggered in the USB 6fire device disconnect path.

2

What event triggers the vulnerable code path?

The issue occurs when the USB 6fire interface is disconnected. If no ALSA card file handles are open, snd_card_free_when_closed() can free the card and its embedded chip structure synchronously before a later write to chip->card.

3

Are active audio clients required for the use-after-free to occur?

No. The described use-after-free specifically arises when snd_card_free_when_closed() is called while no file handles are open, allowing immediate card teardown.

4

What does the fix change in the disconnect sequence?

The fix saves the card pointer before teardown, disconnects the card to block new opens, aborts URBs while the chip remains valid, and frees the card only after those operations complete. This prevents any access to the embedded chip after its card may have been freed.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203