-

CVE-2026-98314

ALSA: pcm: set timer->private_data before registering the PCM timer

In the Linux kernel, the following vulnerability has been resolved:

ALSA: pcm: set timer->private_data before registering the PCM timer

snd_pcm_timer_init() calls snd_device_register() to link the new
struct snd_timer into the global timer list while it still carries
hw.c_resolution = snd_pcm_timer_resolution (and hw.start/hw.stop),
and only afterwards sets timer->private_data = substream.

Once the timer is on the list under register_mutex, a concurrent
reader can already reach it through the same mutex and invoke these
callbacks. /proc/asound/timers does this via c_resolution(), and
snd_timer_open()+snd_timer_start() reach start()/stop() the same way.
All three dereference timer->private_data, which for this brief
window is NULL, giving a NULL-pointer dereference:

  substream = timer->private_data;
  return substream->runtime ? ...   // substream is NULL

Move the private_data/private_free assignment before
snd_device_register() so the timer is never visible on the list
without its private_data set. On the snd_device_register() failure
path, private_free() (snd_pcm_timer_free()) can now run, but it only
does substream->timer = NULL, which is already NULL at that point
since substream->timer is set to the new timer just once, after a
successful registration -- so the failure path stays safe.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < 27f167e117eca310661fbcbacb352ea08face067
Status affected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < 555d168bd98daa46daccc68c908201388c834293
Status affected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < 8c869d5cf5affb20994bdbb60e7d46d65c91b55f
Status affected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < 686c7a6af1eea8d2a919303e4c6bbec3de79dbdc
Status affected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < e1eee8f16628f8b6bcae0a366fd6a2dd65e71edd
Status affected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < d63f5a9f8121fb43c798056d7dd34c58f47185d7
Status affected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < 0b349249d572633d7c8cdeb917623d1676a2b7c3
Status affected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < 1e713f9bb2ac583521f06b0eb4e22440b1e3d078
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 2.6.12
Status affected
Version 0
Version < 2.6.12
Status unaffected
Version <= 5.10.*
Version 5.10.271
Status unaffected
Version <= 5.15.*
Version 5.15.222
Status unaffected
Version <= 6.1.*
Version 6.1.189
Status unaffected
Version <= 6.6.*
Version 6.6.158
Status unaffected
Version <= 6.12.*
Version 6.12.112
Status unaffected
Version <= 6.18.*
Version 6.18.54
Status unaffected
Version <= 7.2.*
Version 7.2.8
Status unaffected
Version <= *
Version 7.3-rc4
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.18% 0.073
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/27f167e117eca310661fbcbacb352ea08face067
https://git.kernel.org/stable/c/555d168bd98daa46daccc68c908201388c834293
https://git.kernel.org/stable/c/8c869d5cf5affb20994bdbb60e7d46d65c91b55f
https://git.kernel.org/stable/c/686c7a6af1eea8d2a919303e4c6bbec3de79dbdc
https://git.kernel.org/stable/c/e1eee8f16628f8b6bcae0a366fd6a2dd65e71edd
https://git.kernel.org/stable/c/d63f5a9f8121fb43c798056d7dd34c58f47185d7
https://git.kernel.org/stable/c/0b349249d572633d7c8cdeb917623d1676a2b7c3
https://git.kernel.org/stable/c/1e713f9bb2ac583521f06b0eb4e22440b1e3d078