CVE-2026-98264

Source
https://cve.org/CVERecord?id=CVE-2026-98264
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98264.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-98264
Downstream
Published
2026-10-06T08:45:27Z
Modified
2026-10-08T02:52:55Z
Summary
ALSA: virtio: reset device before deleting virtqueues
Details

In the Linux kernel, the following vulnerability has been resolved:

ALSA: virtio: reset device before deleting virtqueues

virtsnd_remove() and virtsnd_freeze() delete the virtqueues before resetting the device. del_vqs() frees the vring backing, but does not provide a generic device quiesce operation. In particular, modern virtio-pci keeps enabled queues active until the device is reset.

Reset the device before deleting the virtqueues so it can no longer access the vring memory when that memory is released. This also covers probe failures after DRIVER_OK, which unwind through virtsnd_remove().

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98264.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
de3a9980d8c34b2479173e809afa820473db676a
Fixed
8edc3669e3e22f0123a1114c3a03df9abc4cd465
Fixed
830012feadc228a938514a6487862dcf56af7e66
Fixed
500a8401415ab085555785c3c339747e378abd36
Fixed
3e24b4a6acfd3bedb2200334595facd767c9a897
Fixed
f070cce7cb361d5389b18f3ff6bd3d25a7596369
Fixed
6c05d00af307560e6a9f1631d6270d3df5aa2272

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98264.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.13.0
Fixed
6.1.189
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.158
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.112
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.54
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98264.json"