CVE-2026-45963: ASoC: nau8821: Cancel delayed work on component remove

Published May 27, 2026
·
Updated

ASoC: nau8821: Cancel delayed work on component remove

Affected Software

2 affected components
Linux Linux kernel (snd_soc_nau8821 ASoC driver)
Linux Linux kernel>=5.16<6.19.4

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    In the ASoC nau8821 driver, ensure that during component driver remove/unload you cancel any pending jack detection work (cancel/unschedule nau8821_jdet_work or wait for it to complete) so that snd_soc_dapm_disable_pin is not called after the driver/core resources have been removed.

    Linux kernel (ASoC nau8821 driver) Cancel pending jack detection delayed work on component remove = Cancel/flush nau8821_jdet_work (unschedule jdet_work) before unloading the driver

Event History

May 27, 2026
CVE Published
via MITRE·12:18 PM
Data Sourced
via MITRE·12:18 PM
Description
Data Sourced
via NVD·02:17 PM
RemedyDescriptionSeverityWeaknessAffected Software
May 28, 2026
Data Sourced
via Microsoft·08:11 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which systems are exposed to this issue?

Systems using the Linux kernel's snd_soc_nau8821 ASoC driver are exposed when the driver can be unloaded while its jack-detection delayed work is pending. The supplied crash report identifies Valve Jupiter hardware, but the data does not limit the issue to that platform.

2

What must happen for exploitation or failure to occur?

A local user with low privileges must trigger or cause removal/unloading of the NAU8821 component driver while jack-detection work is pending. When the queued work later executes after component removal, it can crash the kernel.

3

Is this a remote attack vector?

No. The CVSS vector specifies local access, low attack complexity, low privileges required, and no user interaction.

4

What is the impact if the issue is triggered?

The documented impact is a kernel crash, resulting in high availability impact. The CVSS vector reports no confidentiality or integrity impact.

5

What mitigation is indicated when patching is not immediately possible?

Avoid unloading or removing the NAU8821 component driver while jack-detection work may be pending. The fix cancels unscheduled jack-detection work or waits for it to finish before driver removal.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203