CVE-2026-98055 Overview
CVE-2026-98055 is a Linux kernel vulnerability in the ASoC Intel avs driver. The flaw affects the PCI probe path, specifically avs_pci_probe(), which fails to check the return code of snd_hdac_ext_bus_get_ml_capabilities(). The driver also neglects to clean up the hlink list when subsequent initialization steps fail. The fix updates the error path to verify the capability-fetch result and to release bus resources before returning on failure.
Critical Impact
Improper error handling during HD-Audio multi-link capability fetch can leave kernel resources in an inconsistent state, leading to resource leaks or instability on Intel audio hardware initialization failures.
Affected Products
- Linux kernel ASoC Intel avs driver
- Systems using Intel HD-Audio with multi-link (ML) extensions
- Distributions shipping affected mainline kernel versions prior to the referenced stable commits
Discovery Timeline
- 2026-09-25 - CVE-2026-98055 published to NVD
- 2026-09-30 - Last updated in NVD database
Technical Details for CVE-2026-98055
Vulnerability Analysis
The vulnerability resides in avs_pci_probe() within the Intel Audio-DSP (avs) ASoC driver. During probe, the driver calls snd_hdac_ext_bus_get_ml_capabilities() to enumerate HD-Audio multi-link capabilities. The original code did not inspect the return value of this call. A failure in capability retrieval could allow probe to continue with partially initialized bus state.
A second defect in the same function compounds the issue. When snd_hdac_ext_bus_get_ml_capabilities() succeeds but a later step in avs_pci_probe() fails, the hlink list previously allocated by the HD-Audio extended bus is not released before the error path returns. This leaves linked-list entries dangling in kernel memory.
The net effect is a kernel resource management defect on the device initialization path. Repeated probe failures or driver reload cycles can accumulate leaked objects and leave the HD-Audio bus state inconsistent.
Root Cause
The root cause is missing error checking combined with incomplete cleanup. The driver treats snd_hdac_ext_bus_get_ml_capabilities() as infallible and omits an unwind step for the hlink list when later probe stages fail. This is a classic error-handling omission in a device-probe sequence.
Attack Vector
The defect is reached through the normal PCI probe flow for Intel audio controllers. Triggering the error paths requires conditions in which the HD-Audio extended bus capability query fails or a subsequent probe step fails. Exploitation requires local access to a system with the affected hardware and driver loaded. The vulnerability is a reliability and resource-management issue rather than a confirmed remote attack vector.
The fix is distributed across four stable-tree commits referenced below. See the upstream patches for the exact code changes applied to avs_pci_probe().
Detection Methods for CVE-2026-98055
Indicators of Compromise
- Kernel log entries from the avs driver indicating probe failure or HD-Audio multi-link capability errors.
- dmesg warnings referencing snd_hdac_ext_bus_get_ml_capabilities returning non-zero status.
- Increasing kernel slab usage associated with HD-Audio extended-link objects after repeated module load or device rebind cycles.
Detection Strategies
- Inventory running kernel versions against the fixed stable-tree commits listed in the upstream references.
- Monitor system logs for repeated avs driver probe failures on Intel audio-equipped endpoints.
- Use kernel memory diagnostics such as kmemleak on test systems that exhibit audio initialization errors.
Monitoring Recommendations
- Centralize kernel logs from Linux endpoints and alert on avs or snd_hdac_ext error patterns.
- Track kernel version drift across the fleet to confirm patch adoption.
- Correlate driver probe failures with hardware events to isolate affected systems.
How to Mitigate CVE-2026-98055
Immediate Actions Required
- Identify Linux hosts running kernels that predate the fix referenced in the upstream stable commits.
- Schedule kernel updates to a version containing the patched avs_pci_probe() error path.
- Prioritize systems with Intel HD-Audio hardware where the avs driver is loaded.
Patch Information
The fix is applied through the following upstream commits in the Linux stable tree:
- Kernel Git Commit 04447cd1
- Kernel Git Commit 2d96325e
- Kernel Git Commit 498bf266
- Kernel Git Commit 559ea14b
Apply the kernel update supplied by your Linux distribution that incorporates these commits.
Workarounds
- If a patched kernel is not immediately available, unload the snd_soc_avs module on systems where Intel audio functionality is not required.
- Blacklist the avs driver via /etc/modprobe.d/ on affected non-audio workloads to prevent probe execution.
- Avoid repeated driver rebind operations on systems exhibiting HD-Audio capability-fetch failures until patched.
# Verify kernel version and check if avs module is loaded
uname -r
lsmod | grep snd_soc_avs
# Temporarily unload the driver if audio is not required
sudo modprobe -r snd_soc_avs
# Persistently blacklist the module until the kernel is patched
echo "blacklist snd_soc_avs" | sudo tee /etc/modprobe.d/blacklist-avs.conf
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.