PT-2026-94568 · Linux · Linux Kernel
CVE-2026-90220
·
Published
2026-09-17
·
Updated
2026-09-24
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
An issue exists in the ALSA sequencer where the
bounce error event() function leaks a kernel memory address to userspace. When a queued variable-length event fails, the data.ext.ptr variable points to the event, and if that event is variable-length, its own data.ext.ptr contains the address of its first extension cell. This address is sent verbatim through snd seq expand var event(). An unprivileged client can trigger this by setting SNDRV SEQ FILTER BOUNCE, queueing a variable-length event to a non-existent port, and reading the bounce back, resulting in the leak of eight bytes on 64-bit systems.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel