CVE-2026-98308

Source
https://cve.org/CVERecord?id=CVE-2026-98308
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98308.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-98308
Downstream
Published
2026-10-06T08:46:05Z
Modified
2026-10-08T02:52:57Z
Summary
ALSA: hda: trace PCM open only after assigning a stream
Details

In the Linux kernel, the following vulnerability has been resolved:

ALSA: hda: trace PCM open only after assigning a stream

Stream assignment can fail when hardware streams are exhausted. Move the tracepoint after the NULL check because its payload accesses the assigned stream tag.

Detected by static analysis and reviewed with AI-assisted source auditing.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98308.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
184865085b88789fc8a355cc16ceff25f82f63ba
Fixed
5a4c974dee03cc46eac43c82f33e34ec94f0b348
Fixed
fba079ea22822248c82c3a999c88676d05b17bda
Fixed
3c6ca6d9342f4a0be7c1413180e11023d13b5cde
Fixed
0a52ba6d3b268bb82f0ec4cb861bc68d252369c0
Fixed
5c89e7965220e85d06ae4c58adb7d7bb6da2440c
Fixed
8477643cb91c9e09ac1b11890eef421ae63e53f7
Fixed
3db8afba2d210b7d80cd5cc6b76d7f46daa9b47a
Fixed
c9e6e5f38bf75276605f1952b22285f5f3abcaff

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98308.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.2.0
Fixed
5.10.271
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.222
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.189
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.158
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.112
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.54
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98308.json"