PT-2026-106643 · Linux · Linux
CVE-2026-98314
·
Published
2026-10-06
·
Updated
2026-10-06
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
ALSA: pcm: set timer->private data before registering the PCM timer
snd pcm timer init() calls snd device register() to link the new
struct snd timer into the global timer list while it still carries
hw.c resolution = snd pcm timer resolution (and hw.start/hw.stop),
and only afterwards sets timer->private data = substream.
Once the timer is on the list under register mutex, a concurrent
reader can already reach it through the same mutex and invoke these
callbacks. /proc/asound/timers does this via c resolution(), and
snd timer open()+snd timer start() reach start()/stop() the same way.
All three dereference timer->private data, which for this brief
window is NULL, giving a NULL-pointer dereference:
substream = timer->private data;
return substream->runtime ? ... // substream is NULL
Move the private data/private free assignment before
snd device register() so the timer is never visible on the list
without its private data set. On the snd device register() failure
path, private free() (snd pcm timer free()) can now run, but it only
does substream->timer = NULL, which is already NULL at that point
since substream->timer is set to the new timer just once, after a
successful registration -- so the failure path stays safe.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux