7.8

CVE-2026-80716

ALSA: pcm: wake linked drain waiters on unlink

In the Linux kernel, the following vulnerability has been resolved:

ALSA: pcm: wake linked drain waiters on unlink

snd_pcm_drain() on a linked stream parks an on-stack wait entry on the
drained peer's runtime->sleep, and after schedule_timeout() removes it
only if that peer is still found in the caller's group.  If group
membership changes during the wait and the sleep ends by signal or
timeout (so autoremove_wake_function() does not run), finish_wait() is
skipped and snd_pcm_drain() returns with the entry still queued on that
stream's sleep list; a later wake_up() then walks a freed stack frame.
This is reachable by unlinking either the drained or the draining stream.

Unlike the close path (snd_pcm_drop() -> snd_pcm_post_stop()),
snd_pcm_unlink() never wakes the sleep queues.  Wake every group member
under the group lock before the membership change, so a linked drainer is
released and drops its entry while the streams are still grouped.

The window was opened when snd_pcm_link_rwsem stopped being held across
the wait and the removal became conditional on group membership (see
Fixes). The later switch to finish_wait() kept that conditional removal,
so the signal/timeout case remained.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version f57f3df03a8e6010e321fa0258d3e054713c3cb7
Version < c172e4c53321ee6429955295ea133bc3597a3ca9
Status affected
Version f57f3df03a8e6010e321fa0258d3e054713c3cb7
Version < 3035bb784cea3f338934f5042dd3f35225a51b2e
Status affected
Version f57f3df03a8e6010e321fa0258d3e054713c3cb7
Version < 1c1b7e8e545ce65e40f65b55c432765e058ea98f
Status affected
Version f57f3df03a8e6010e321fa0258d3e054713c3cb7
Version < e8b784a3f4fba3ea9c4d05138ecfa784a069627f
Status affected
Version f57f3df03a8e6010e321fa0258d3e054713c3cb7
Version < e8315330e4ec09c0cac625515400e13d0ee22b81
Status affected
Version f57f3df03a8e6010e321fa0258d3e054713c3cb7
Version < 2940cc3cf43c72126b74ee6376314c195382023a
Status affected
Version f57f3df03a8e6010e321fa0258d3e054713c3cb7
Version < db09bc4ab19ce548a078240d2374792523953500
Status affected
Version f57f3df03a8e6010e321fa0258d3e054713c3cb7
Version < f495b6c4c8594122918552c9be2b51eb71647cd9
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 5.1
Status affected
Version 0
Version < 5.1
Status unaffected
Version <= 5.10.*
Version 5.10.265
Status unaffected
Version <= 5.15.*
Version 5.15.216
Status unaffected
Version <= 6.1.*
Version 6.1.183
Status unaffected
Version <= 6.6.*
Version 6.6.151
Status unaffected
Version <= 6.12.*
Version 6.12.103
Status unaffected
Version <= 6.18.*
Version 6.18.44
Status unaffected
Version <= 7.1.*
Version 7.1.8
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.12% 0.021
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/c172e4c53321ee6429955295ea133bc3597a3ca9
https://git.kernel.org/stable/c/3035bb784cea3f338934f5042dd3f35225a51b2e
https://git.kernel.org/stable/c/1c1b7e8e545ce65e40f65b55c432765e058ea98f
https://git.kernel.org/stable/c/e8b784a3f4fba3ea9c4d05138ecfa784a069627f
https://git.kernel.org/stable/c/e8315330e4ec09c0cac625515400e13d0ee22b81
https://git.kernel.org/stable/c/2940cc3cf43c72126b74ee6376314c195382023a
https://git.kernel.org/stable/c/db09bc4ab19ce548a078240d2374792523953500
https://git.kernel.org/stable/c/f495b6c4c8594122918552c9be2b51eb71647cd9