PT-2026-106643 · Linux · Linux

CVE-2026-98314

·

Publicado

2026-10-06

·

Atualizado

2026-10-06

Nenhuma

Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
ALSA: pcm: set timer->private data before registering the PCM timer
snd pcm timer init() calls snd device register() to link the new struct snd timer into the global timer list while it still carries hw.c resolution = snd pcm timer resolution (and hw.start/hw.stop), and only afterwards sets timer->private data = substream.
Once the timer is on the list under register mutex, a concurrent reader can already reach it through the same mutex and invoke these callbacks. /proc/asound/timers does this via c resolution(), and snd timer open()+snd timer start() reach start()/stop() the same way. All three dereference timer->private data, which for this brief window is NULL, giving a NULL-pointer dereference:
substream = timer->private data; return substream->runtime ? ... // substream is NULL
Move the private data/private free assignment before snd device register() so the timer is never visible on the list without its private data set. On the snd device register() failure path, private free() (snd pcm timer free()) can now run, but it only does substream->timer = NULL, which is already NULL at that point since substream->timer is set to the new timer just once, after a successful registration -- so the failure path stays safe.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2026-98314

Produtos afetados

Linux