Answer in brief
CVE-2026-80716 records a Unknown severity vulnerability in ALSA: pcm: wake linked drain waiters on unlink. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=f57f3df03a8e6010e321fa0258d3e054713c3cb7 <c172e4c53321ee6429955295ea133bc3597a3ca9 || >=f57f3df03a8e6010e321fa0258d3e054713c3cb7 <3035bb784cea3f338934f5042dd3f35225a51b2e || >=f57f3df03a8e6010e321fa0258d3e054713c3cb7 <1c1b7e8e545ce65e40f65b55c432765e058ea98f || >=f57f3df03a8e6010e321fa0258d3e054713c3cb7 <e8b784a3f4fba3ea9c4d05138ecfa784a069627f || >=f57f3df03a8e6010e321fa0258d3e054713c3cb7 <e8315330e4ec09c0cac625515400e13d0ee22b81 || >=f57f3df03a8e6010e321fa0258d3e054713c3cb7 <2940cc3cf43c72126b74ee6376314c195382023a || >=f57f3df03a8e6010e321fa0258d3e054713c3cb7 <db09bc4ab19ce548a078240d2374792523953500 || >=f57f3df03a8e6010e321fa0258d3e054713c3cb7 <f495b6c4c8594122918552c9be2b51eb71647cd9 | c172e4c53321ee6429955295ea133bc3597a3ca9, 3035bb784cea3f338934f5042dd3f35225a51b2e, 1c1b7e8e545ce65e40f65b55c432765e058ea98f, e8b784a3f4fba3ea9c4d05138ecfa784a069627f, e8315330e4ec09c0cac625515400e13d0ee22b81, 2940cc3cf43c72126b74ee6376314c195382023a, db09bc4ab19ce548a078240d2374792523953500, f495b6c4c8594122918552c9be2b51eb71647cd9 |
| Linux/Linuxgeneric | 5.1 | Not reported |
Published upstream
Aug 28, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 28, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 28, 2026
In the Linux kernel, the following vulnerability has been resolved: ALSA: pcm: wake linked drain waiters on unlink snd_pcm_drain() on a linked stream parks an on-stack wait entry on the drained peer's runtime->sleep, and after schedule_timeout() removes it only if that peer is still found in the caller's group. If group membership changes during the wait and the sleep ends by signal or timeout (so autoremove_wake_function() does not run), finish_wait() is skipped and snd_pcm_drain() returns with the entry still queued on that stream's sleep list; a later wake_up() then walks a freed stack frame. This is reachable by unlinking either the drained or the draining stream. Unlike the close path (snd_pcm_drop() -> snd_pcm_post_stop()), snd_pcm_unlink() never wakes the sleep queues. Wake every group member under the group lock before the membership change, so a linked drainer is released and drops its entry while the streams are still grouped. The window was opened when snd_pcm_link_rwsem stopped being held across the wait and the removal became conditional on group membership (see Fixes). The later switch to finish_wait() kept that conditional removal, so the signal/timeout case remained.
Quoted source text, attributed separately from HOL analysis.