CVE-2026-72486

Source
https://cve.org/CVERecord?id=CVE-2026-72486
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72486.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-72486
Downstream
Published
2026-08-15T05:57:22.821Z
Modified
2026-08-18T03:31:19.178091696Z
Summary
mailbox: mtk-adsp: fix UAF during device teardown
Details

In the Linux kernel, the following vulnerability has been resolved:

mailbox: mtk-adsp: fix UAF during device teardown

When the SOF audio driver fails to initialize (e.g. firmware boot timeout), its devres unwind frees the sndsofdev object that the mailbox client (mtk-adsp-ipc) reaches via chan->cl->rxcallback. The mtk-adsp-mailbox shutdown clears the mailbox command registers but leaves the IRQ line unmasked, so a late interrupt can still queue a threaded handler after mboxfreechannel() had cleared chan->cl, and mboxchanreceiveddata() would then trigger UAF:

BUG: KASAN: slab-use-after-free in sofipc3validatefwversion sofipc3validatefwversion sofipc3dorxwork sofipc3rxmsg mt8196dsphandlerequest mtkadspipcrecv mboxchanreceiveddata mtkadspmboxisr irqthreadfn Freed by task ...: kfree devresreleaseall reallyprobe ... (sof-audio-of-mt8196 probe failure)

The crash was observed roughly three seconds after the failed probe.

disableirq() in shutdown and enableirq() in startup. disableirq() also waits for any in-flight interrupts, so by the time mboxfreechannel() proceeds to clear chan->cl no rxcallback can run.

In addition, request the IRQ with IRQFNOAUTOEN so it stays masked between probe and the first client bind — otherwise an early interrupt can crash on chan->cl == NULL in mboxchanreceived_data().

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72486.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
af2dfa96c52d042df5deb29fb6e32d3ff4d76a61
Fixed
b6337a08a63eef8efcffe3c01d479badda6bbbdb
Fixed
e519c1d8c5efb5cd8d4c5bb3fe39b1bbb812bdb9
Fixed
fc6c3deb1d4c0adebf7dee0b8af4082af3f17690
Fixed
7d881615fb6373f71fc628b3f00186aeca87a3d5
Fixed
25d6ea6c76e1b1b7c57337b2f8f1b6fc8d5c52bc
Fixed
b57d1a40bc43258372fa1f4d39305e093947a262

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72486.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.18.0
Fixed
6.1.178
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.145
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.97
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.40
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72486.json"