-

CVE-2026-64479

ALSA: seq: Fix uninitialised heap leak in snd_seq_event_dup()

In the Linux kernel, the following vulnerability has been resolved:

ALSA: seq: Fix uninitialised heap leak in snd_seq_event_dup()

snd_seq_event_dup() copies an incoming event into a pool cell and, in
the UMP-enabled build, clears the trailing cell->ump.raw.extra word that
the memcpy() did not cover.  The guard deciding whether to clear it
compares the copied size against sizeof(cell->event):

	memcpy(&cell->ump, event, size);
	if (size < sizeof(cell->event))
		cell->ump.raw.extra = 0;

For a legacy (non-UMP) event, size == sizeof(struct snd_seq_event) ==
sizeof(cell->event), so the condition is false and the extra word keeps
stale data.  The cell pool is allocated with kvmalloc() (not zeroed) and
cells are reused via a free list, so that word holds uninitialised heap
or leftover event data.

When such a cell is delivered to a UMP client (client->midi_version > 0)
that set SNDRV_SEQ_FILTER_NO_CONVERT -- so the legacy event reaches it
unconverted -- snd_seq_read() reads it out as the larger struct
snd_seq_ump_event and copies the stale word to user space, a 4-byte
kernel heap infoleak to an unprivileged /dev/snd/seq client.

Compare against sizeof(cell->ump) instead, so the trailing word is zeroed
for every event shorter than the UMP cell.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
Produkt Linux
Default Statusunaffected
Version 6389f2c135311c4ce7c08c3b29145c8f95aacf1f
Version < d7649aa11089a93ea2285c210397aa67e5800766
Status affected
Version d7e2ce72833bb23a82b4201fbed7214cc04a4a8c
Version < a224c84e5d3d35708c082c84ad12d81d90762195
Status affected
Version 46397622a3fa8372b8fda0f04b33d16923b03b1b
Version < ea672a9f6cc38f06fe69dd2c257ef8a3d4db179a
Status affected
Version 46397622a3fa8372b8fda0f04b33d16923b03b1b
Version < fb1aa5082847b98f44f9c6272aee9d0dca9244f0
Status affected
Version 46397622a3fa8372b8fda0f04b33d16923b03b1b
Version < 651ba82fe2a144bc7356d940bfd235c3810b0549
Status affected
Version 46397622a3fa8372b8fda0f04b33d16923b03b1b
Version < 6ded42615fa1f4949925afd0a8a9e1ab3bf96202
Status affected
Version 46397622a3fa8372b8fda0f04b33d16923b03b1b
Version < 435990e25bf1f4af3e6df12a6fbfd1f7ba4a97d4
Status affected
HerstellerLinux
Produkt Linux
Default Statusaffected
Version 6.5
Status affected
Version 0
Version < 6.5
Status unaffected
Version <= 6.6.*
Version 6.6.145
Status unaffected
Version <= 6.12.*
Version 6.12.96
Status unaffected
Version <= 6.18.*
Version 6.18.39
Status unaffected
Version <= 7.1.*
Version 7.1.4
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.18% 0.079
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/d7649aa11089a93ea2285c210397aa67e5800766
https://git.kernel.org/stable/c/a224c84e5d3d35708c082c84ad12d81d90762195
https://git.kernel.org/stable/c/ea672a9f6cc38f06fe69dd2c257ef8a3d4db179a
https://git.kernel.org/stable/c/fb1aa5082847b98f44f9c6272aee9d0dca9244f0
https://git.kernel.org/stable/c/651ba82fe2a144bc7356d940bfd235c3810b0549
https://git.kernel.org/stable/c/6ded42615fa1f4949925afd0a8a9e1ab3bf96202
https://git.kernel.org/stable/c/435990e25bf1f4af3e6df12a6fbfd1f7ba4a97d4