PT-2026-98595 · Linux · Linux Kernel
CVE-2026-97931
·
Published
2026-09-25
·
Updated
2026-10-07
CVSS v3.1
7.0
High
| Vector | AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
An issue exists in the ALSA us122l driver where the hwdep mmap callback fails to clear the
VM MAYWRITE flag on read-buffer mappings created with PROT READ, even after rejecting initially writable mappings. A process with O RDWR access to the hwdep node can use mprotect() to upgrade the mapping to writable. This allows an attacker to modify the read size member of struct usb stream, which is used by the fault handler to determine read buffer pages and by usb stream free() during memory release. Manipulating read size can lead to accessing pages beyond the intended allocation or causing free pages exact() to release incorrect memory pages.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel