7.8

CVE-2026-90207

ALSA: seq: midi: Serialize input teardown with event_input

In the Linux kernel, the following vulnerability has been resolved:

ALSA: seq: midi: Serialize input teardown with event_input

snd_midi_input_event() must not be running while a rawmidi substream is
closing, since this can lead to the trigger state becoming out-of-step
through this sequence in snd_rawmidi_input_trigger():

	snd_rawmidi_input_trigger(up=0)
					snd_midi_input_event()
					 -> snd_rawmidi_kernel_read()
					     -> snd_rawmidi_input_trigger(up=1)
	  -> cancel_work_sync()

which ends with the underlying device being active unexpectedly.

When this is called from close_substream(), further input can re-trigger
the input event leaving it running after rawmidi_release_priv() has set
rfile->rmidi to NULL which leads to:

	Unable to handle kernel NULL pointer dereference at virtual address 00000000000000b0
	Call trace:
	 snd_midi_input_event+0x3c/0x134 [snd_seq_midi] (P)
	 snd_rawmidi_input_event_work+0x1c/0x2c
	 process_one_work+0x150/0x3a4
	 worker_thread+0x190/0x318

Apply a similar approach to commit ef7607ab1c8ad ("ALSA: seq: midi:
Serialize output teardown with event_input") which fixed the same issue
in the output direction, but updated to use RCU following Takashi Iwai's
proposed follow-on patch [1].

With this change in place, midisynth_unsubscribe() clears the input file
so snd_midi_input_event() will not re-trigger the stream and will be
quiesced by the cancel_work_sync() in snd_rawmidi_input_trigger().

[1] https://lore.kernel.org/linux-sound/20260813144224.753399-1-tiwai@suse.de/
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < de76a2b47582cd6dba2e15f024681bf377ecc94a
Status affected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < 89d986897aff7275b42e075e556731b8353366af
Status affected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < 6290afaae54c7a9fa3bca3b4d5433e6d83e8669d
Status affected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < 210c193a9ef1312fab153948c6928e4cfaa1f03b
Status affected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < 282a3ef9e4b63b2f6823bbbb3c1a90b002cdaf12
Status affected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < 403f7f3ad3808a0096d84cf228fab68dc253fd9d
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 2.6.12
Status affected
Version 0
Version < 2.6.12
Status unaffected
Version <= 6.1.*
Version 6.1.188
Status unaffected
Version <= 6.6.*
Version 6.6.157
Status unaffected
Version <= 6.12.*
Version 6.12.110
Status unaffected
Version <= 6.18.*
Version 6.18.52
Status unaffected
Version <= 7.2.*
Version 7.2.6
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.16% 0.061
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/de76a2b47582cd6dba2e15f024681bf377ecc94a
https://git.kernel.org/stable/c/89d986897aff7275b42e075e556731b8353366af
https://git.kernel.org/stable/c/6290afaae54c7a9fa3bca3b4d5433e6d83e8669d
https://git.kernel.org/stable/c/210c193a9ef1312fab153948c6928e4cfaa1f03b
https://git.kernel.org/stable/c/282a3ef9e4b63b2f6823bbbb3c1a90b002cdaf12
https://git.kernel.org/stable/c/403f7f3ad3808a0096d84cf228fab68dc253fd9d