CVE-2026-72486

Source
https://cve.org/CVERecord?id=CVE-2026-72486
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72486.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-72486
Downstream
Published
2026-08-15T05:57:22Z
Modified
2026-08-18T03:31:19Z
Summary
mailbox: mtk-adsp: fix UAF during device teardown
Details

In the Linux kernel, the following vulnerability has been resolved:

mailbox: mtk-adsp: fix UAF during device teardown

When the SOF audio driver fails to initialize (e.g. firmware boot timeout), its devres unwind frees the snd_sof_dev object that the mailbox client (mtk-adsp-ipc) reaches via chan->cl->rx_callback. The mtk-adsp-mailbox shutdown clears the mailbox command registers but leaves the IRQ line unmasked, so a late interrupt can still queue a threaded handler after mbox_free_channel() had cleared chan->cl, and mbox_chan_received_data() would then trigger UAF:

BUG: KASAN: slab-use-after-free in sof_ipc3_validate_fw_version sof_ipc3_validate_fw_version sof_ipc3_do_rx_work sof_ipc3_rx_msg mt8196_dsp_handle_request mtk_adsp_ipc_recv mbox_chan_received_data mtk_adsp_mbox_isr irq_thread_fn Freed by task ...: kfree devres_release_all really_probe ... (sof-audio-of-mt8196 probe failure)

The crash was observed roughly three seconds after the failed probe.

disable_irq() in shutdown and enable_irq() in startup. disable_irq() also waits for any in-flight interrupts, so by the time mbox_free_channel() proceeds to clear chan->cl no rx_callback can run.

In addition, request the IRQ with IRQF_NO_AUTOEN so it stays masked between probe and the first client bind — otherwise an early interrupt can crash on chan->cl == NULL in mbox_chan_received_data().

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72486.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
af2dfa96c52d042df5deb29fb6e32d3ff4d76a61
Fixed
b6337a08a63eef8efcffe3c01d479badda6bbbdb
Fixed
e519c1d8c5efb5cd8d4c5bb3fe39b1bbb812bdb9
Fixed
fc6c3deb1d4c0adebf7dee0b8af4082af3f17690
Fixed
7d881615fb6373f71fc628b3f00186aeca87a3d5
Fixed
25d6ea6c76e1b1b7c57337b2f8f1b6fc8d5c52bc
Fixed
b57d1a40bc43258372fa1f4d39305e093947a262

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72486.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.18.0
Fixed
6.1.178
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.145
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.97
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.40
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72486.json"