PT-2026-106643 · Linux · Linux
CVE-2026-98314
·
Publicado
2026-10-06
·
Atualizado
2026-10-06
Nenhuma
Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
ALSA: pcm: set timer->private data before registering the PCM timer
snd pcm timer init() calls snd device register() to link the new
struct snd timer into the global timer list while it still carries
hw.c resolution = snd pcm timer resolution (and hw.start/hw.stop),
and only afterwards sets timer->private data = substream.
Once the timer is on the list under register mutex, a concurrent
reader can already reach it through the same mutex and invoke these
callbacks. /proc/asound/timers does this via c resolution(), and
snd timer open()+snd timer start() reach start()/stop() the same way.
All three dereference timer->private data, which for this brief
window is NULL, giving a NULL-pointer dereference:
substream = timer->private data;
return substream->runtime ? ... // substream is NULL
Move the private data/private free assignment before
snd device register() so the timer is never visible on the list
without its private data set. On the snd device register() failure
path, private free() (snd pcm timer free()) can now run, but it only
does substream->timer = NULL, which is already NULL at that point
since substream->timer is set to the new timer just once, after a
successful registration -- so the failure path stays safe.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Linux