CVE-2026-98066: Linux

EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: ALSA: caiaq: Fix potential double-free at error path The fix for caiaq driver's resource management to handle the errors tries to release the resources in a common destructor call, but as a sashiko review for another patch suggested, some of the audio resources such as URBs have been already freed, and this may lead to a double-free. For addressing the double-free, call the common destructor function from each place, and assure that the resource pointers get cleared.

Affected products

  • Linux Linux: from 5.10.258, before 5.10.271 (fixed in 5.10.271); from 5.15.209, before 5.15.222 (fixed in 5.15.222); from 6.1.175, before 6.1.189 (fixed in 6.1.189); from 6.6.140, before 6.6.158 (fixed in 6.6.158); from 6.12.86, before 6.12.111 (fixed in 6.12.111); from 6.18.27, before 6.18.53 (fixed in 6.18.53); …

Published 2026-09-25. Last modified 2026-10-03.