7.8
CVE-2026-90207
- EPSS 0.16%
- Veröffentlicht 17.09.2026 16:07:22
- Zuletzt bearbeitet 18.09.2026 18:17:46
- Erkennungen
ALSA: seq: midi: Serialize input teardown with event_input
In the Linux kernel, the following vulnerability has been resolved:
ALSA: seq: midi: Serialize input teardown with event_input
snd_midi_input_event() must not be running while a rawmidi substream is
closing, since this can lead to the trigger state becoming out-of-step
through this sequence in snd_rawmidi_input_trigger():
snd_rawmidi_input_trigger(up=0)
snd_midi_input_event()
-> snd_rawmidi_kernel_read()
-> snd_rawmidi_input_trigger(up=1)
-> cancel_work_sync()
which ends with the underlying device being active unexpectedly.
When this is called from close_substream(), further input can re-trigger
the input event leaving it running after rawmidi_release_priv() has set
rfile->rmidi to NULL which leads to:
Unable to handle kernel NULL pointer dereference at virtual address 00000000000000b0
Call trace:
snd_midi_input_event+0x3c/0x134 [snd_seq_midi] (P)
snd_rawmidi_input_event_work+0x1c/0x2c
process_one_work+0x150/0x3a4
worker_thread+0x190/0x318
Apply a similar approach to commit ef7607ab1c8ad ("ALSA: seq: midi:
Serialize output teardown with event_input") which fixed the same issue
in the output direction, but updated to use RCU following Takashi Iwai's
proposed follow-on patch [1].
With this change in place, midisynth_unsubscribe() clears the input file
so snd_midi_input_event() will not re-trigger the stream and will be
quiesced by the cancel_work_sync() in snd_rawmidi_input_trigger().
[1] https://lore.kernel.org/linux-sound/20260813144224.753399-1-tiwai@suse.de/Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version <
de76a2b47582cd6dba2e15f024681bf377ecc94a
Status
affected
Version
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version <
89d986897aff7275b42e075e556731b8353366af
Status
affected
Version
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version <
6290afaae54c7a9fa3bca3b4d5433e6d83e8669d
Status
affected
Version
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version <
210c193a9ef1312fab153948c6928e4cfaa1f03b
Status
affected
Version
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version <
282a3ef9e4b63b2f6823bbbb3c1a90b002cdaf12
Status
affected
Version
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version <
403f7f3ad3808a0096d84cf228fab68dc253fd9d
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
2.6.12
Status
affected
Version
0
Version <
2.6.12
Status
unaffected
Version <=
6.1.*
Version
6.1.188
Status
unaffected
Version <=
6.6.*
Version
6.6.157
Status
unaffected
Version <=
6.12.*
Version
6.12.110
Status
unaffected
Version <=
6.18.*
Version
6.18.52
Status
unaffected
Version <=
7.2.*
Version
7.2.6
Status
unaffected
Version <=
*
Version
7.3-rc1
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.16% | 0.061 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
https://git.kernel.org/stable/c/de76a2b47582cd6dba2e15f024681bf377ecc94a
https://git.kernel.org/stable/c/89d986897aff7275b42e075e556731b8353366af
https://git.kernel.org/stable/c/6290afaae54c7a9fa3bca3b4d5433e6d83e8669d
https://git.kernel.org/stable/c/210c193a9ef1312fab153948c6928e4cfaa1f03b
https://git.kernel.org/stable/c/282a3ef9e4b63b2f6823bbbb3c1a90b002cdaf12
https://git.kernel.org/stable/c/403f7f3ad3808a0096d84cf228fab68dc253fd9d