-

CVE-2026-90220

ALSA: seq: Don't leak the extension cell pointer in the bounce payload

In the Linux kernel, the following vulnerability has been resolved:

ALSA: seq: Don't leak the extension cell pointer in the bounce payload

The bounce_error_event() embeds the failed event in the bounce payload
by pointing data.ext.ptr at it.  When that event is a queued
variable-length event, its own data.ext.ptr holds the address of its
first extension cell, put there by snd_seq_event_dup().  The payload
goes out verbatim through snd_seq_expand_var_event(), so the address
reaches userspace.

That is the same address commit 705dd6dcbc0e ("ALSA: seq: Clear
variable event pointer on read") removed from the event header.  The
read path still clears it there, just above the call that expands the
payload.

Embed a sanitised copy instead, treated exactly as snd_seq_read()
treats the header.  A stack copy is enough because delivery is
synchronous and snd_seq_event_dup() copies before returning.

An unprivileged client reaches this by setting SNDRV_SEQ_FILTER_BOUNCE,
queueing a variable-length event to a port that does not exist and
reading the bounce back.  Eight bytes on 64-bit, from its own pool.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 93d260ce43a81df579c98bee92b91316df9c1c57
Version < 42c3f856d13a91a0d4c302a0c6854813621136db
Status affected
Version dae23c545eb5a2be3b27a82fd0f611894fb8ab69
Version < b1e8d40663997aacaa198f37ce6893e07aaba77a
Status affected
Version efc86691e4d8083d9e380ea95042c2cf679f65fd
Version < 6e6e471eef1d5d8cb056c7d364023fe048249204
Status affected
Version efc86691e4d8083d9e380ea95042c2cf679f65fd
Version < 59e1592d3c270ff4642d5d6dc55c545306eb0693
Status affected
Version 0527a56cb327021cb73167cfddf0e49efa043500
Status affected
Version 6.12.97
Version < 6.12.110
Status affected
Version 6.18.40
Version < 6.18.52
Status affected
Version 7.1.5
Version < 7.2
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 7.2
Status affected
Version 0
Version < 7.2
Status unaffected
Version <= 6.12.*
Version 6.12.110
Status unaffected
Version <= 6.18.*
Version 6.18.52
Status unaffected
Version <= 7.2.*
Version 7.2.6
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.2% 0.102
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/42c3f856d13a91a0d4c302a0c6854813621136db
https://git.kernel.org/stable/c/b1e8d40663997aacaa198f37ce6893e07aaba77a
https://git.kernel.org/stable/c/6e6e471eef1d5d8cb056c7d364023fe048249204
https://git.kernel.org/stable/c/59e1592d3c270ff4642d5d6dc55c545306eb0693