{"apiVersion":"1.0","identifier":"CVE-2026-80716","description":"In the Linux kernel, the following vulnerability has been resolved: ALSA: pcm: wake linked drain waiters on unlink snd_pcm_drain() on a linked stream parks an on-stack wait entry on the drained peer-s runtime->sleep, and after schedule_timeout() removes it only if that peer is still found in the caller-s group. If group membership changes during the wait and the sleep ends by signal or timeout (so autoremove_wake_function() does not run), finish_wait() is skipped and snd_pcm_drain() returns with the entry still queued on that stream-s sleep list; a later wake_up() then walks a freed stack frame. This is reachable by unlinking either the drained or the draining stream. Unlike the close path (snd_pcm_drop() -> snd_pcm_post_stop()), snd_pcm_unlink() never wakes the sleep queues. Wake every group member under the group lock before the membership change, so a linked drainer is released and drops its entry while the streams are still grouped. The window was opened when snd_pcm_link_rwsem stopped being held across the wait and the removal became conditional on group membership (see Fixes). The later switch to finish_wait() kept that conditional removal, so the signal/timeout case remained.","publishedAt":"2026-08-28T08:16:57","lastModifiedAt":"2026-08-28T08:16:57","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-80716","cvssScore":null,"cvssVector":"Pending","epssProbability":0.00164,"riskScore":0,"affectedProduct":"Linux kernel","affectedVersions":"unknown","vulnerabilityType":"Kernel","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-80716","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-80716","en":"https://www.redsauce.net/en/cves/CVE-2026-80716","fr":"https://www.redsauce.net/fr/cves/CVE-2026-80716","pt":"https://www.redsauce.net/pt/cves/CVE-2026-80716","de":"https://www.redsauce.net/de/cves/CVE-2026-80716","sk":"https://www.redsauce.net/sk/cves/CVE-2026-80716","el":"https://www.redsauce.net/el/cves/CVE-2026-80716"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-80716"}}