Answer in brief
CVE-2026-98066 records a Unknown severity vulnerability in ALSA: caiaq: Fix potential double-free at error path. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=6251e3e256337a30160ef59ab1580dde4d1acd28 <2883d65a3d9a8d9a682cdb003e6ab7fb28bb17f8 || >=e59ecd4ee3a450db6cb4e4ecaa3efdd593f80056 <1dd715ca0568e4833ed5878f49b028b449941096 || >=28abd224db4a49560b452115bca3672a20e45b2f <b629ae7b3eddc6812d5af3614b8c1bd76d65fa75 || >=28abd224db4a49560b452115bca3672a20e45b2f <3b26ceef88c110f4d188387cffa0df78657be904 || da938aa9fc7826901921dcea225948ab21a97e45 || 09616e25f502080ba684fc7fcf959d1376ab756d || b956e48371f2ff72b76be9a829800ecec963bd45 || f537e3ad69609f6924a4db6b4a7f6561f5288bdd || 096dd8519cf2f768e9e14f224b627f7aaee1a9c5 || >=6.12.86 <6.12.111 || >=6.18.27 <6.18.53 || >=5.10.258 <5.11 || >=5.15.209 <5.16 || >=6.1.175 <6.2 || >=6.6.140 <6.7 || >=7.0.4 <7.1 | 2883d65a3d9a8d9a682cdb003e6ab7fb28bb17f8, 1dd715ca0568e4833ed5878f49b028b449941096, b629ae7b3eddc6812d5af3614b8c1bd76d65fa75, 3b26ceef88c110f4d188387cffa0df78657be904, 6.12.111, 6.18.53, 5.11, 5.16, 6.2, 6.7, 7.1 |
| Linux/Linuxgeneric | 7.1 | Not reported |
Published upstream
Sep 25, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 25, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 25, 2026
In the Linux kernel, the following vulnerability has been resolved: ALSA: caiaq: Fix potential double-free at error path The fix for caiaq driver's resource management to handle the errors tries to release the resources in a common destructor call, but as a sashiko review for another patch suggested, some of the audio resources such as URBs have been already freed, and this may lead to a double-free. For addressing the double-free, call the common destructor function from each place, and assure that the resource pointers get cleared.
Quoted source text, attributed separately from HOL analysis.