PT-2026-94568 · Linux · Linux Kernel

CVE-2026-90220

·

Published

2026-09-17

·

Updated

2026-09-24

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the ALSA sequencer where the bounce error event() function leaks a kernel memory address to userspace. When a queued variable-length event fails, the data.ext.ptr variable points to the event, and if that event is variable-length, its own data.ext.ptr contains the address of its first extension cell. This address is sent verbatim through snd seq expand var event(). An unprivileged client can trigger this by setting SNDRV SEQ FILTER BOUNCE, queueing a variable-length event to a non-existent port, and reading the bounce back, resulting in the leak of eight bytes on 64-bit systems.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-90220
OPENSUSE-SU-2026:11880-1

Affected Products

Linux Kernel