CVE-2026-89895

Source
https://cve.org/CVERecord?id=CVE-2026-89895
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89895.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-89895
Downstream
Published
2026-09-16T10:31:56Z
Modified
2026-09-17T03:47:27Z
Summary
media: cobalt: Avoid freeing ALSA private data twice
Details

In the Linux kernel, the following vulnerability has been resolved:

media: cobalt: Avoid freeing ALSA private data twice

snd_cobalt_card_create() stores cobsc in sc->private_data and installs snd_cobalt_card_private_free() as sc->private_free. From that point, snd_card_free(sc) releases cobsc through the ALSA card cleanup path.

If cobalt_alsa_init() fails after snd_cobalt_card_create(), the err_exit_free path calls snd_card_free(sc) and then kfree(cobsc). That second free releases the same object again.

Remove the explicit kfree(cobsc) and leave ownership with the ALSA card.

This issue was found by a static analysis checker and confirmed by manual source review.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89895.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
85756a069c55e0315ac5990806899cfb607b987f
Fixed
75bbf45e3a954e292ae26832d2df40ca2e3ee452
Fixed
fe65028ee72a7e07e572b351891bd7a1f8917d33
Fixed
61dfa8ded5efc3a25d331fa9ce5cebb85531fe70
Fixed
42e00371f83c3fc7b99a36bf0229c74ad5d3c7d8
Fixed
6cbc8a73b3464ebeccc49987b7233b6b087b8504
Fixed
cb1218da234ea15fa14d90e2d049d686874d7aa3
Fixed
8c6610e230b9355cf7df5a338a0592c0f088c00b
Fixed
3a7d6b9c4cb5ac18cbd3f1c7f8c7b159c42ba0b1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89895.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.2.0
Fixed
5.10.270
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.221
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.188
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.157
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.110
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.51
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89895.json"