PT-2026-98778 · Linux · Linux
CVE-2026-98116
·
Publicado
2026-09-25
·
Atualizado
2026-09-25
CVSS v3.1
7.8
Alta
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
In the Linux kernel, the following vulnerability has been resolved:
ALSA: pcm: Serialize PCM mmap with buffer reallocation to fix page UAF
snd pcm hw params() and snd pcm hw free() guard buffer reallocation
with an mmap count check performed under the PCM stream lock, but the
lock is released long before the buffer is actually freed:
snd pcm sync stop(), constraint refinement and do free pages() all
happen in between. snd pcm mmap data(), on the other hand, takes no
lock at all: it validates against the old buffer's state and
dma bytes, remaps its pages into the VMA, and only then increments
mmap count.
A concurrent mmap() can therefore slip in between the check and the
free. remap pfn range() installs writable PTEs for the old buffer's
pages without taking page references, and the subsequent
do free pages() returns those pages to the page allocator while the
VMA still maps them. This leaves a stale, writable mapping of freed
pages: a page-level use-after-free that can be leveraged for local
privilege escalation.
Make snd pcm mmap data() participate in the buffer-access scheme
introduced for hw params/hw free: acquire runtime->buffer accessing
before validating and remapping, and release it afterwards. Buffer
reallocation already fails with -EBUSY while accessors are active,
and the mmap side now fails with -EBUSY while a reallocation is in
progress, so the validate/remap sequence and the check/free sequence
can no longer interleave.
A reproducer that turns this race into a stale writable mapping of
the freed DMA buffer pages is available on request.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Linux