# CVE-2026-46090

## Summary

- **CVE ID:** CVE-2026-46090
- **Severity:** HIGH
- **CVSS Score:** 7.8 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
- **CWE:** N/A
- **Published:** May 27, 2026
- **Last Modified:** Sep 14, 2026

## Description

In the Linux kernel, the following vulnerability has been resolved:

ALSA: aloop: Fix peer runtime UAF during format-change stop

loopback_check_format() may stop the capture side when playback starts
with parameters that no longer match a running capture stream. Commit
826af7fa62e3 ("ALSA: aloop: Fix racy access at PCM trigger") moved
the peer lookup under cable->lock, but the actual snd_pcm_stop() still
runs after dropping that lock.

A concurrent close can clear the capture entry from cable->streams[] and
detach or free its runtime while the playback trigger path still holds a
stale peer substream pointer.

Keep a per-cable count of in-flight peer stops before dropping
cable->lock, and make free_cable() wait for those stops before
detaching the runtime. This preserves the existing behavior while
making the peer runtime lifetime explicit.

## Affected Products

- Linux — Linux (597603d615d2b19a9e451d8cfac24372856a522d)
- Linux — Linux (2.6.37)
- Linux — Linux (0)
- Linux — Linux (6.12.88)
- Linux — Linux (6.18.27)
- Linux — Linux (7.0.4)
- Linux — Linux (7.1-rc2)
- Linux — Linux (7.1)
- Linux — Linux (5.10.259)
- Linux — Linux (5.15.210)
- Linux — Linux (6.1.188)
- Linux — Linux (6.6.157)

## References

- [CNA](https://git.kernel.org/stable/c/03f52a9c170431e8f10e156b9dc0dae80b3e9198)
- [CNA](https://git.kernel.org/stable/c/bdd9503c3d222d2735b56c7a8b4422ccf3de6e5c)
- [CNA](https://git.kernel.org/stable/c/5d45e34bf001344e2966dabca1897561bbc9e913)
- [CNA](https://git.kernel.org/stable/c/e5c33cdc6f402eab8abd36ecf436b22c9d3a8aff)
- [CNA](https://git.kernel.org/stable/c/83bd62fa9620ac98d5d694bde14c50f98c8e7189)
- [CNA](https://git.kernel.org/stable/c/345c24b2bcf0923dfae1ab41497351c68214ff76)
- [redhat-SADP](https://access.redhat.com/security/cve/CVE-2026-46090)
- [redhat-SADP](https://bugzilla.redhat.com/show_bug.cgi?id=2481980)
- [redhat-SADP](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-46090.json)
- [redhat-SADP](https://access.redhat.com/errata/RHSA-2026:33215)
- [redhat-SADP](https://access.redhat.com/errata/RHSA-2026:30848)
- [redhat-SADP](https://access.redhat.com/errata/RHSA-2026:27353)
- [redhat-SADP](https://access.redhat.com/errata/RHSA-2026:27354)
- [redhat-SADP](https://access.redhat.com/errata/RHSA-2026:33685)
- [redhat-SADP](https://access.redhat.com/errata/RHSA-2026:33899)
- [redhat-SADP](https://access.redhat.com/errata/RHSA-2026:33900)
- [redhat-SADP](https://access.redhat.com/errata/RHSA-2026:34095)
- [redhat-SADP](https://access.redhat.com/errata/RHSA-2026:34443)
- [redhat-SADP](https://access.redhat.com/errata/RHSA-2026:34094)
- [redhat-SADP](https://access.redhat.com/errata/RHSA-2026:35844)
- [redhat-SADP](https://access.redhat.com/errata/RHSA-2026:35863)
- [redhat-SADP](https://access.redhat.com/errata/RHSA-2026:35896)
- [redhat-SADP](https://access.redhat.com/errata/RHSA-2026:41236)
- [CNA](https://git.kernel.org/stable/c/3727a3541788412c393eec236ad228d72efe19c7)
- [CNA](https://git.kernel.org/stable/c/d258cdce50ff3e02392917258e81a0ce9555c327)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.10%
- **EPSS Percentile:** 1.1

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-18._