7
CVE-2026-97931
- EPSS 0.14%
- Veröffentlicht 25.09.2026 10:22:47
- Zuletzt bearbeitet 03.10.2026 11:18:10
- Erkennungen
ALSA: us122l: Prevent write upgrades for read mappings
In the Linux kernel, the following vulnerability has been resolved: ALSA: us122l: Prevent write upgrades for read mappings The hwdep mmap callback rejects read-buffer mappings that are initially writable, but leaves VM_MAYWRITE set on mappings created with PROT_READ. A process that can open the hwdep node O_RDWR can later use mprotect() to make the mapping writable. The read allocation begins with struct usb_stream. Its read_size member is used by the fault handler to decide which pages belong to the read buffer. The read VMA intentionally remains expandable because pcm_usb_stream uses mremap() after reading that size. Changing read_size first can therefore map and access pages beyond the allocation. The same member is also consumed by usb_stream_free(), where changing it can make free_pages_exact() release pages outside the allocation. Clear VM_MAYWRITE for read-buffer mappings after rejecting an initially writable VMA. This keeps the separate output-buffer mapping writable while preventing later permission upgrades.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
030a07e441296c372f946cd4065b5d831d8dc40c
Version <
cbc1f954ce67d739d41d1f0757d29850353ebb6a
Status
affected
Version
030a07e441296c372f946cd4065b5d831d8dc40c
Version <
becb89036a1320ef0a77da2d27935ac0704345c4
Status
affected
Version
030a07e441296c372f946cd4065b5d831d8dc40c
Version <
6a5f5a5a32c78e67701f1d0f26bc87af68895604
Status
affected
Version
030a07e441296c372f946cd4065b5d831d8dc40c
Version <
938e8d6cee8d36f24669dfdcd3717e081eb32d64
Status
affected
Version
030a07e441296c372f946cd4065b5d831d8dc40c
Version <
64a87950239867682cde128020e1a47088295e5c
Status
affected
Version
030a07e441296c372f946cd4065b5d831d8dc40c
Version <
d9c537b14f4982f17b103e3a2cfeee4bee6bc026
Status
affected
Version
030a07e441296c372f946cd4065b5d831d8dc40c
Version <
0eb9dd4774af0ac4d1fd105ef2b0a1f6cec06f2f
Status
affected
Version
030a07e441296c372f946cd4065b5d831d8dc40c
Version <
71c610aeb1770302ac9c9e0b9a4ecd37f1311928
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
2.6.28
Status
affected
Version
0
Version <
2.6.28
Status
unaffected
Version <=
5.10.*
Version
5.10.271
Status
unaffected
Version <=
5.15.*
Version
5.15.222
Status
unaffected
Version <=
6.1.*
Version
6.1.189
Status
unaffected
Version <=
6.6.*
Version
6.6.158
Status
unaffected
Version <=
6.12.*
Version
6.12.111
Status
unaffected
Version <=
6.18.*
Version
6.18.53
Status
unaffected
Version <=
7.2.*
Version
7.2.7
Status
unaffected
Version <=
*
Version
7.3-rc3
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.14% | 0.031 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | 7 | 1 | 5.9 |
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
|
https://git.kernel.org/stable/c/64a87950239867682cde128020e1a47088295e5c
https://git.kernel.org/stable/c/d9c537b14f4982f17b103e3a2cfeee4bee6bc026
https://git.kernel.org/stable/c/0eb9dd4774af0ac4d1fd105ef2b0a1f6cec06f2f
https://git.kernel.org/stable/c/71c610aeb1770302ac9c9e0b9a4ecd37f1311928
https://git.kernel.org/stable/c/6a5f5a5a32c78e67701f1d0f26bc87af68895604
https://git.kernel.org/stable/c/938e8d6cee8d36f24669dfdcd3717e081eb32d64
https://git.kernel.org/stable/c/becb89036a1320ef0a77da2d27935ac0704345c4
https://git.kernel.org/stable/c/cbc1f954ce67d739d41d1f0757d29850353ebb6a