PT-2026-106643 · Linux · Linux

CVE-2026-98314

·

Published

2026-10-06

·

Updated

2026-10-06

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
ALSA: pcm: set timer->private data before registering the PCM timer
snd pcm timer init() calls snd device register() to link the new struct snd timer into the global timer list while it still carries hw.c resolution = snd pcm timer resolution (and hw.start/hw.stop), and only afterwards sets timer->private data = substream.
Once the timer is on the list under register mutex, a concurrent reader can already reach it through the same mutex and invoke these callbacks. /proc/asound/timers does this via c resolution(), and snd timer open()+snd timer start() reach start()/stop() the same way. All three dereference timer->private data, which for this brief window is NULL, giving a NULL-pointer dereference:
substream = timer->private data; return substream->runtime ? ... // substream is NULL
Move the private data/private free assignment before snd device register() so the timer is never visible on the list without its private data set. On the snd device register() failure path, private free() (snd pcm timer free()) can now run, but it only does substream->timer = NULL, which is already NULL at that point since substream->timer is set to the new timer just once, after a successful registration -- so the failure path stays safe.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-98314

Affected Products

Linux