CVE-2026-43204

MEDIUM

ASoC: qcom: q6asm: drop DSP responses for closed data streams

Title source: cna
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: ASoC: qcom: q6asm: drop DSP responses for closed data streams 'Commit a354f030dbce ("ASoC: qcom: q6asm: handle the responses after closing")' attempted to ignore DSP responses arriving after a stream had been closed. However, those responses were still handled, causing lockups. Fix this by unconditionally dropping all DSP responses associated with closed data streams.

Scores

CVSS v3 5.5
EPSS 0.0001
EPSS Percentile 3.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

Status published
Products (9)
Linux/Linux < 4.18
Linux/Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 - 3249251eac6081d5169ba09f2d9cca66ab0cab0d
Linux/Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 - 8a066a81ee0c1b6cdbd81393536c3b2d19ccef25
Linux/Linux 4.18
Linux/Linux 6.19.6 - 6.19.*
Linux/Linux 68fd8480bb7baaf361e983f75d8571f25e017c67 - 3249251eac6081d5169ba09f2d9cca66ab0cab0d
Linux/Linux 68fd8480bb7baaf361e983f75d8571f25e017c67 - 8a066a81ee0c1b6cdbd81393536c3b2d19ccef25
Linux/Linux 7.0
linux/linux_kernel 4.18 - 6.19.6
Published May 06, 2026
Tracked Since May 06, 2026