CVE-2026-98116
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Summary
In the Linux kernel, the following vulnerability has been resolved:
ALSA: pcm: Serialize PCM mmap with buffer reallocation to fix page UAF
snd_pcm_hw_params() and snd_pcm_hw_free() guard buffer reallocation with an mmap_count check performed under the PCM stream lock, but the lock is released long before the buffer is actually freed: snd_pcm_sync_stop(), constraint refinement and do_free_pages() all happen in between. snd_pcm_mmap_data(), on the other hand, takes no lock at all: it validates against the old buffer's state and dma_bytes, remaps its pages into the VMA, and only then increments mmap_count.
A concurrent mmap() can therefore slip in between the check and the free. remap_pfn_range() installs writable PTEs for the old buffer's pages without taking page references, and the subsequent do_free_pages() returns those pages to the page allocator while the VMA still maps them. This leaves a stale, writable mapping of freed pages: a page-level use-after-free that can be leveraged for local privilege escalation.
Make snd_pcm_mmap_data() participate in the buffer-access scheme introduced for hw_params/hw_free: acquire runtime->buffer_accessing before validating and remapping, and release it afterwards. Buffer reallocation already fails with -EBUSY while accessors are active, and the mmap side now fails with -EBUSY while a reallocation is in progress, so the validate/remap sequence and the check/free sequence can no longer interleave.
A reproducer that turns this race into a stale writable mapping of the freed DMA buffer pages is available on request.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 92ee3c60ec9fe64404dc035e7c41277d74aa26cb < cbc7ec97601d09b74e05e44470fa6b0bcdabf3f5 | affected |
| Linux | Linux | 92ee3c60ec9fe64404dc035e7c41277d74aa26cb < fd137bf8149bc6460f9b7b1fc292025da04cb9ee | affected |
| Linux | Linux | 92ee3c60ec9fe64404dc035e7c41277d74aa26cb < 8c1882dfee8f404d118020664b73eb4592172226 | affected |
| Linux | Linux | 92ee3c60ec9fe64404dc035e7c41277d74aa26cb < 9b110a9dcecc59516c77cb3c0caf1f492f75df2d | affected |
| Linux | Linux | a42aa926843acca96c0dfbde2e835b8137f2f092 | affected |
| Linux | Linux | 9cb6c40a6ebe4a0cfc9d6a181958211682cffea9 | affected |
| Linux | Linux | fbeb492694ce0441053de57699e1e2b7bc148a69 | affected |
| Linux | Linux | 0f6947f5f5208f6ebd4d76a82a4757e2839a23f8 | affected |
| Linux | Linux | 33061d0fba51d2bf70a2ef9645f703c33fe8e438 | affected |
| Linux | Linux | 0090c13cbbdffd7da079ac56f80373a9a1be0bf8 | affected |
| Linux | Linux | 1bbf82d9f961414d6c76a08f7f843ea068e0ab7b | affected |
| Linux | Linux | 4.14.279 < 4.15 | affected |
| Linux | Linux | 4.19.243 < 4.20 | affected |
| Linux | Linux | 5.4.193 < 5.5 | affected |
| Linux | Linux | 5.10.109 < 5.11 | affected |
| Linux | Linux | 5.15.32 < 5.16 | affected |
| Linux | Linux | 5.16.18 < 5.17 | affected |
| Linux | Linux | 5.17.1 < 5.18 | affected |
| Linux | Linux | 5.18 | affected |
| Linux | Linux | 0 < 5.18 | unaffected |
| Linux | Linux | 6.12.111 <= 6.12.* | unaffected |
| Linux | Linux | 6.18.53 <= 6.18.* | unaffected |
| Linux | Linux | 7.2.7 <= 7.2.* | unaffected |
| Linux | Linux | 7.3-rc2 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/cbc7ec97601d09b74e05e44470fa6b0bcdabf3f5
- https://git.kernel.org/stable/c/fd137bf8149bc6460f9b7b1fc292025da04cb9ee
- https://git.kernel.org/stable/c/8c1882dfee8f404d118020664b73eb4592172226
- https://git.kernel.org/stable/c/9b110a9dcecc59516c77cb3c0caf1f492f75df2d
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.