CVE-2026-46048: ALSA: caiaq: fix usb_dev refcount leak on probe failure
Published May 27, 2026
·Updated
ALSA: caiaq: fix usbdev refcount leak on probe failure
Affected Software
7 affected componentsFixes available
Linux ALSA caiaq
Linux Linux kernel>=6.6.136<6.6.140
Linux Linux kernel>=6.12.84<6.12.86
Linux Linux kernel>=6.18.25<6.18.27
Linux Linux kernel>=7.0.2<7.0.4
Linux Linux kernel=7.1-rc1
Microsoft azl3 kernel 6.6.139.1-1<6.6.141.1-1
6.6.141.1-1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.6.141.1-1
Event History
May 27, 2026
CVE Published
via MITRE·12:57 PM
Data Sourced
via MITRE·12:57 PM
Description
Data Sourced
via NVD·02:17 PM
RemedyDescriptionSeverityAffected Software
May 28, 2026
Data Sourced
via Microsoft·08:01 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·08:01 AM
Affected Software
Updated
via Microsoft·08:01 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2026-46048?
CVE-2026-46048 has a medium severity rating of 5.5.
2
How do I fix CVE-2026-46048?
To mitigate CVE-2026-46048, update the Linux kernel to a version that includes the fix for the refcount leak.
3
What does CVE-2026-46048 affect?
CVE-2026-46048 affects the ALSA caiaq driver in the Linux kernel.
4
What is the risk associated with CVE-2026-46048?
CVE-2026-46048 presents a risk level of 32, indicating potential system disruption due to a refcount leak.
5
When was CVE-2026-46048 published?
CVE-2026-46048 was published on May 27, 2026.