7

CVE-2026-97931

ALSA: us122l: Prevent write upgrades for read mappings

In the Linux kernel, the following vulnerability has been resolved:

ALSA: us122l: Prevent write upgrades for read mappings

The hwdep mmap callback rejects read-buffer mappings that are initially
writable, but leaves VM_MAYWRITE set on mappings created with PROT_READ.
A process that can open the hwdep node O_RDWR can later use mprotect() to
make the mapping writable.

The read allocation begins with struct usb_stream. Its read_size member is
used by the fault handler to decide which pages belong to the read buffer.
The read VMA intentionally remains expandable because pcm_usb_stream uses
mremap() after reading that size. Changing read_size first can therefore
map and access pages beyond the allocation. The same member is also
consumed by usb_stream_free(), where changing it can make
free_pages_exact() release pages outside the allocation.

Clear VM_MAYWRITE for read-buffer mappings after rejecting an initially
writable VMA. This keeps the separate output-buffer mapping writable while
preventing later permission upgrades.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 030a07e441296c372f946cd4065b5d831d8dc40c
Version < cbc1f954ce67d739d41d1f0757d29850353ebb6a
Status affected
Version 030a07e441296c372f946cd4065b5d831d8dc40c
Version < becb89036a1320ef0a77da2d27935ac0704345c4
Status affected
Version 030a07e441296c372f946cd4065b5d831d8dc40c
Version < 6a5f5a5a32c78e67701f1d0f26bc87af68895604
Status affected
Version 030a07e441296c372f946cd4065b5d831d8dc40c
Version < 938e8d6cee8d36f24669dfdcd3717e081eb32d64
Status affected
Version 030a07e441296c372f946cd4065b5d831d8dc40c
Version < 64a87950239867682cde128020e1a47088295e5c
Status affected
Version 030a07e441296c372f946cd4065b5d831d8dc40c
Version < d9c537b14f4982f17b103e3a2cfeee4bee6bc026
Status affected
Version 030a07e441296c372f946cd4065b5d831d8dc40c
Version < 0eb9dd4774af0ac4d1fd105ef2b0a1f6cec06f2f
Status affected
Version 030a07e441296c372f946cd4065b5d831d8dc40c
Version < 71c610aeb1770302ac9c9e0b9a4ecd37f1311928
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 2.6.28
Status affected
Version 0
Version < 2.6.28
Status unaffected
Version <= 5.10.*
Version 5.10.271
Status unaffected
Version <= 5.15.*
Version 5.15.222
Status unaffected
Version <= 6.1.*
Version 6.1.189
Status unaffected
Version <= 6.6.*
Version 6.6.158
Status unaffected
Version <= 6.12.*
Version 6.12.111
Status unaffected
Version <= 6.18.*
Version 6.18.53
Status unaffected
Version <= 7.2.*
Version 7.2.7
Status unaffected
Version <= *
Version 7.3-rc3
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.14% 0.031
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7 1 5.9
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/64a87950239867682cde128020e1a47088295e5c
https://git.kernel.org/stable/c/d9c537b14f4982f17b103e3a2cfeee4bee6bc026
https://git.kernel.org/stable/c/0eb9dd4774af0ac4d1fd105ef2b0a1f6cec06f2f
https://git.kernel.org/stable/c/71c610aeb1770302ac9c9e0b9a4ecd37f1311928
https://git.kernel.org/stable/c/6a5f5a5a32c78e67701f1d0f26bc87af68895604
https://git.kernel.org/stable/c/938e8d6cee8d36f24669dfdcd3717e081eb32d64
https://git.kernel.org/stable/c/becb89036a1320ef0a77da2d27935ac0704345c4
https://git.kernel.org/stable/c/cbc1f954ce67d739d41d1f0757d29850353ebb6a