CVE-2026-80716

Source
https://cve.org/CVERecord?id=CVE-2026-80716
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80716.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-80716
Downstream
Published
2026-08-28T06:53:14.286Z
Modified
2026-08-29T03:47:17.349523281Z
Summary
ALSA: pcm: wake linked drain waiters on unlink
Details

In the Linux kernel, the following vulnerability has been resolved:

ALSA: pcm: wake linked drain waiters on unlink

sndpcmdrain() on a linked stream parks an on-stack wait entry on the drained peer's runtime->sleep, and after scheduletimeout() removes it only if that peer is still found in the caller's group. If group membership changes during the wait and the sleep ends by signal or timeout (so autoremovewakefunction() does not run), finishwait() is skipped and sndpcmdrain() returns with the entry still queued on that stream's sleep list; a later wake_up() then walks a freed stack frame. This is reachable by unlinking either the drained or the draining stream.

Unlike the close path (sndpcmdrop() -> sndpcmpoststop()), sndpcm_unlink() never wakes the sleep queues. Wake every group member under the group lock before the membership change, so a linked drainer is released and drops its entry while the streams are still grouped.

The window was opened when sndpcmlinkrwsem stopped being held across the wait and the removal became conditional on group membership (see Fixes). The later switch to finishwait() kept that conditional removal, so the signal/timeout case remained.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/80xxx/CVE-2026-80716.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
f57f3df03a8e6010e321fa0258d3e054713c3cb7
Fixed
c172e4c53321ee6429955295ea133bc3597a3ca9
Fixed
3035bb784cea3f338934f5042dd3f35225a51b2e
Fixed
1c1b7e8e545ce65e40f65b55c432765e058ea98f
Fixed
e8b784a3f4fba3ea9c4d05138ecfa784a069627f
Fixed
e8315330e4ec09c0cac625515400e13d0ee22b81
Fixed
2940cc3cf43c72126b74ee6376314c195382023a
Fixed
db09bc4ab19ce548a078240d2374792523953500
Fixed
f495b6c4c8594122918552c9be2b51eb71647cd9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80716.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.1.0
Fixed
5.10.265
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.216
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.183
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.151
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.103
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.44
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80716.json"