Answer in brief
CVE-2026-89895 records a Unknown severity vulnerability in media: cobalt: Avoid freeing ALSA private data twice. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=85756a069c55e0315ac5990806899cfb607b987f <75bbf45e3a954e292ae26832d2df40ca2e3ee452 || >=85756a069c55e0315ac5990806899cfb607b987f <fe65028ee72a7e07e572b351891bd7a1f8917d33 || >=85756a069c55e0315ac5990806899cfb607b987f <61dfa8ded5efc3a25d331fa9ce5cebb85531fe70 || >=85756a069c55e0315ac5990806899cfb607b987f <42e00371f83c3fc7b99a36bf0229c74ad5d3c7d8 || >=85756a069c55e0315ac5990806899cfb607b987f <6cbc8a73b3464ebeccc49987b7233b6b087b8504 || >=85756a069c55e0315ac5990806899cfb607b987f <cb1218da234ea15fa14d90e2d049d686874d7aa3 || >=85756a069c55e0315ac5990806899cfb607b987f <8c6610e230b9355cf7df5a338a0592c0f088c00b || >=85756a069c55e0315ac5990806899cfb607b987f <3a7d6b9c4cb5ac18cbd3f1c7f8c7b159c42ba0b1 | 75bbf45e3a954e292ae26832d2df40ca2e3ee452, fe65028ee72a7e07e572b351891bd7a1f8917d33, 61dfa8ded5efc3a25d331fa9ce5cebb85531fe70, 42e00371f83c3fc7b99a36bf0229c74ad5d3c7d8, 6cbc8a73b3464ebeccc49987b7233b6b087b8504, cb1218da234ea15fa14d90e2d049d686874d7aa3, 8c6610e230b9355cf7df5a338a0592c0f088c00b, 3a7d6b9c4cb5ac18cbd3f1c7f8c7b159c42ba0b1 |
| Linux/Linuxgeneric | 4.2 | Not reported |
Published upstream
Sep 16, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 16, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 16, 2026
In the Linux kernel, the following vulnerability has been resolved: media: cobalt: Avoid freeing ALSA private data twice snd_cobalt_card_create() stores cobsc in sc->private_data and installs snd_cobalt_card_private_free() as sc->private_free. From that point, snd_card_free(sc) releases cobsc through the ALSA card cleanup path. If cobalt_alsa_init() fails after snd_cobalt_card_create(), the err_exit_free path calls snd_card_free(sc) and then kfree(cobsc). That second free releases the same object again. Remove the explicit kfree(cobsc) and leave ownership with the ALSA card. This issue was found by a static analysis checker and confirmed by manual source review.
Quoted source text, attributed separately from HOL analysis.