{"id":"CVE-2026-98264","title":"In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: virtio: reset device before deleting virtqueues\n\nvirtsnd_remove() and virtsnd_freeze() delete the virtqueues before\nresetting the device","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: virtio: reset device before deleting virtqueues\n\nvirtsnd_remove() and virtsnd_freeze() delete the virtqueues before\nresetting the device. del_vqs() frees the vrin…","severity":"none","vendor":"Linux","product":"Linux","affected":["Linux >= de3a9980d8c34b2479173e809afa820473db676a < 8edc3669e3e22f0123a1114c3a03df9abc4cd465","Linux >= de3a9980d8c34b2479173e809afa820473db676a < 830012feadc228a938514a6487862dcf56af7e66","Linux >= de3a9980d8c34b2479173e809afa820473db676a < 500a8401415ab085555785c3c339747e378abd36","Linux >= de3a9980d8c34b2479173e809afa820473db676a < 3e24b4a6acfd3bedb2200334595facd767c9a897","Linux >= de3a9980d8c34b2479173e809afa820473db676a < f070cce7cb361d5389b18f3ff6bd3d25a7596369","Linux >= de3a9980d8c34b2479173e809afa820473db676a < 6c05d00af307560e6a9f1631d6270d3df5aa2272","Linux 5.13"],"published":"2026-10-06","updated":"2026-10-06","sourceUpdated":"2026-10-06T09:18:15.650","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-98264","references":[{"url":"https://git.kernel.org/stable/c/3e24b4a6acfd3bedb2200334595facd767c9a897","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/500a8401415ab085555785c3c339747e378abd36","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6c05d00af307560e6a9f1631d6270d3df5aa2272","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/830012feadc228a938514a6487862dcf56af7e66","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8edc3669e3e22f0123a1114c3a03df9abc4cd465","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f070cce7cb361d5389b18f3ff6bd3d25a7596369","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-06T08:50:17.425Z","slug":"CVE-2026-98264","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nALSA: virtio: reset device before deleting virtqueues\n\nvirtsnd_remove() and virtsnd_freeze() delete the virtqueues before\nresetting the device. del_vqs() frees the vring backing, but does not\nprovide a generic device quiesce operation. In particular, modern\nvirtio-pci keeps enabled queues active until the device is reset.\n\nReset the device before deleting the virtqueues so it can no longer\naccess the vring memory when that memory is released. This also covers\nprobe failures after DRIVER_OK, which unwind through virtsnd_remove().\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}