Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-99465.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-99465
Upstream
Published
2026-09-04T16:18:10Z
Modified
2026-09-05T14:16:57.893070134Z
Summary
CVE-2026-80828 affecting package kernel 6.6.150.1-1
Details

In the Linux kernel, the following vulnerability has been resolved:

ALSA: usb-audio: Complete cleanup after system-resume errors

A failed system resume can leave the card unusable until reboot. usbaudioresume() jumps to errout when sndusbpcmresume() or sndusbmixerresume() fails. The error path skips the out: block, which restores D0 and decrements chip->numsuspended_intf.

The card stays in SNDRVCTLPOWERD3hot, so later control access blocks in sndpowerrefand_wait(). USB core logs an interface resume callback error. It does not retry that callback, so a later callback cannot complete the skipped cleanup.

usbaudiosuspend() increments numsuspendedintf before returning success. A system-resume callback must consume the system-suspend count even if a component resume fails. Otherwise, the stranded count skews later suspend and resume cycles.

Do not apply this cleanup to runtime-resume errors. Runtime PM can retry -EAGAIN or -EBUSY without another suspend callback. The count must continue to describe that suspended interface. Other runtime-resume errors latch runtime_error in the PM core and do not cause an immediate callback retry.

Both parts of the system-resume error path are longstanding. Commit 88a8516a2128a ("ALSA: usbaudio: implement USB autosuspend") introduced errout past the D0 restore. Commit 862b2509d157c ("ALSA: usb-audio: Fix inconsistent card PM state after resume") later moved numsuspended_intf-- into the out: block. The error path now skips both operations.

No third-party code is needed to reach the error path. sndusbmixerresume() ends in sndusbmixeractivate(), which returns the result of usbsubmiturb() for devices that have a mixer status URB. Its mixer->privateresume hook can also fail through scarlett2initnotify(). sndusbpcmresume() issues a SET_CUR request to a UAC3 power domain. It can return -EPIPE or -EIO when the device stalls the request.

Route a component error through out: only when systemsuspend is nonzero. Continue to return runtime-resume errors through errout. Later component resume stages remain skipped. The original error still reaches USB core. A later transfer can fail if the device did not recover.

I reproduced the system-resume failure on an Audient iD14 MkI with an out-of-tree diagnostic mixer resume hook. An injected -EIO on the unpatched core left control readers in uninterruptible sleep in sndpowerrefandwait() until a reboot. With this patch, the same failure restored control access. A second system suspend and resume also succeeded after I disabled fault injection.

References

Affected packages

Azure Linux:3 / kernel

Package

Name
kernel
Purl
pkg:rpm/azure-linux/kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
6.6.150.1-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-99465.json"