7.8

CVE-2026-98116

ALSA: pcm: Serialize PCM mmap with buffer reallocation to fix page UAF

In the Linux kernel, the following vulnerability has been resolved:

ALSA: pcm: Serialize PCM mmap with buffer reallocation to fix page UAF

snd_pcm_hw_params() and snd_pcm_hw_free() guard buffer reallocation
with an mmap_count check performed under the PCM stream lock, but the
lock is released long before the buffer is actually freed:
snd_pcm_sync_stop(), constraint refinement and do_free_pages() all
happen in between.  snd_pcm_mmap_data(), on the other hand, takes no
lock at all: it validates against the old buffer's state and
dma_bytes, remaps its pages into the VMA, and only then increments
mmap_count.

A concurrent mmap() can therefore slip in between the check and the
free.  remap_pfn_range() installs writable PTEs for the old buffer's
pages without taking page references, and the subsequent
do_free_pages() returns those pages to the page allocator while the
VMA still maps them.  This leaves a stale, writable mapping of freed
pages: a page-level use-after-free that can be leveraged for local
privilege escalation.

Make snd_pcm_mmap_data() participate in the buffer-access scheme
introduced for hw_params/hw_free: acquire runtime->buffer_accessing
before validating and remapping, and release it afterwards.  Buffer
reallocation already fails with -EBUSY while accessors are active,
and the mmap side now fails with -EBUSY while a reallocation is in
progress, so the validate/remap sequence and the check/free sequence
can no longer interleave.

A reproducer that turns this race into a stale writable mapping of
the freed DMA buffer pages is available on request.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 33061d0fba51d2bf70a2ef9645f703c33fe8e438
Version < e6cdd2a0470d64073349a970dc1691433804b271
Status affected
Version 92ee3c60ec9fe64404dc035e7c41277d74aa26cb
Version < 9857a75714bb5df4781e4d8b1a1753b1e17bf07a
Status affected
Version 92ee3c60ec9fe64404dc035e7c41277d74aa26cb
Version < cbadf2575d25e7dcc0d4da2717817ae569fbc99b
Status affected
Version 92ee3c60ec9fe64404dc035e7c41277d74aa26cb
Version < cbc7ec97601d09b74e05e44470fa6b0bcdabf3f5
Status affected
Version 92ee3c60ec9fe64404dc035e7c41277d74aa26cb
Version < fd137bf8149bc6460f9b7b1fc292025da04cb9ee
Status affected
Version 92ee3c60ec9fe64404dc035e7c41277d74aa26cb
Version < 8c1882dfee8f404d118020664b73eb4592172226
Status affected
Version 92ee3c60ec9fe64404dc035e7c41277d74aa26cb
Version < 9b110a9dcecc59516c77cb3c0caf1f492f75df2d
Status affected
Version a42aa926843acca96c0dfbde2e835b8137f2f092
Status affected
Version 9cb6c40a6ebe4a0cfc9d6a181958211682cffea9
Status affected
Version fbeb492694ce0441053de57699e1e2b7bc148a69
Status affected
Version 0f6947f5f5208f6ebd4d76a82a4757e2839a23f8
Status affected
Version 0090c13cbbdffd7da079ac56f80373a9a1be0bf8
Status affected
Version 1bbf82d9f961414d6c76a08f7f843ea068e0ab7b
Status affected
Version 5.15.32
Version < 5.15.222
Status affected
Version 4.14.279
Version < 4.15
Status affected
Version 4.19.243
Version < 4.20
Status affected
Version 5.4.193
Version < 5.5
Status affected
Version 5.10.109
Version < 5.11
Status affected
Version 5.16.18
Version < 5.17
Status affected
Version 5.17.1
Version < 5.18
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 5.18
Status affected
Version 0
Version < 5.18
Status unaffected
Version <= 5.15.*
Version 5.15.222
Status unaffected
Version <= 6.1.*
Version 6.1.189
Status unaffected
Version <= 6.6.*
Version 6.6.158
Status unaffected
Version <= 6.12.*
Version 6.12.111
Status unaffected
Version <= 6.18.*
Version 6.18.53
Status unaffected
Version <= 7.2.*
Version 7.2.7
Status unaffected
Version <= *
Version 7.3-rc2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.13% 0.019
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/cbc7ec97601d09b74e05e44470fa6b0bcdabf3f5
https://git.kernel.org/stable/c/fd137bf8149bc6460f9b7b1fc292025da04cb9ee
https://git.kernel.org/stable/c/8c1882dfee8f404d118020664b73eb4592172226
https://git.kernel.org/stable/c/9b110a9dcecc59516c77cb3c0caf1f492f75df2d
https://git.kernel.org/stable/c/9857a75714bb5df4781e4d8b1a1753b1e17bf07a
https://git.kernel.org/stable/c/cbadf2575d25e7dcc0d4da2717817ae569fbc99b
https://git.kernel.org/stable/c/e6cdd2a0470d64073349a970dc1691433804b271