PT-2026-98778 · Linux · Linux

CVE-2026-98116

·

Published

2026-09-25

·

Updated

2026-09-25

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the Linux kernel, the following vulnerability has been resolved:
ALSA: pcm: Serialize PCM mmap with buffer reallocation to fix page UAF
snd pcm hw params() and snd pcm hw free() guard buffer reallocation with an mmap count check performed under the PCM stream lock, but the lock is released long before the buffer is actually freed: snd pcm sync stop(), constraint refinement and do free pages() all happen in between. snd pcm mmap data(), on the other hand, takes no lock at all: it validates against the old buffer's state and dma bytes, remaps its pages into the VMA, and only then increments mmap count.
A concurrent mmap() can therefore slip in between the check and the free. remap pfn range() installs writable PTEs for the old buffer's pages without taking page references, and the subsequent do free pages() returns those pages to the page allocator while the VMA still maps them. This leaves a stale, writable mapping of freed pages: a page-level use-after-free that can be leveraged for local privilege escalation.
Make snd pcm mmap data() participate in the buffer-access scheme introduced for hw params/hw free: acquire runtime->buffer accessing before validating and remapping, and release it afterwards. Buffer reallocation already fails with -EBUSY while accessors are active, and the mmap side now fails with -EBUSY while a reallocation is in progress, so the validate/remap sequence and the check/free sequence can no longer interleave.
A reproducer that turns this race into a stale writable mapping of the freed DMA buffer pages is available on request.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-98116

Affected Products

Linux