CVE-2026-98264

high

Description

In the Linux kernel, the following vulnerability has been resolved: ALSA: virtio: reset device before deleting virtqueues virtsnd_remove() and virtsnd_freeze() delete the virtqueues before resetting the device. del_vqs() frees the vring backing, but does not provide a generic device quiesce operation. In particular, modern virtio-pci keeps enabled queues active until the device is reset. Reset the device before deleting the virtqueues so it can no longer access the vring memory when that memory is released. This also covers probe failures after DRIVER_OK, which unwind through virtsnd_remove().

References

https://git.kernel.org/stable/c/f070cce7cb361d5389b18f3ff6bd3d25a7596369

https://git.kernel.org/stable/c/8edc3669e3e22f0123a1114c3a03df9abc4cd465

https://git.kernel.org/stable/c/830012feadc228a938514a6487862dcf56af7e66

https://git.kernel.org/stable/c/6c05d00af307560e6a9f1631d6270d3df5aa2272

https://git.kernel.org/stable/c/500a8401415ab085555785c3c339747e378abd36

https://git.kernel.org/stable/c/3e24b4a6acfd3bedb2200334595facd767c9a897

https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-93192

Details

Source: Mitre, NVD

Published: 2026-10-06

Updated: 2026-10-06

Risk Information

CVSS v2

Base Score: 6.6

Vector: CVSS2#AV:L/AC:L/Au:N/C:N/I:C/A:C

Severity: Medium

CVSS v3

Base Score: 7.1

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

Severity: High

EPSS

EPSS: 0.00215