CVE-2026-98116

Summary

In the Linux kernel, the following vulnerability has been resolved:

ALSA: pcm: Serialize PCM mmap with buffer reallocation to fix page UAF

snd_pcm_hw_params() and snd_pcm_hw_free() guard buffer reallocation with an mmap_count check performed under the PCM stream lock, but the lock is released long before the buffer is actually freed: snd_pcm_sync_stop(), constraint refinement and do_free_pages() all happen in between. snd_pcm_mmap_data(), on the other hand, takes no lock at all: it validates against the old buffer's state and dma_bytes, remaps its pages into the VMA, and only then increments mmap_count.

A concurrent mmap() can therefore slip in between the check and the free. remap_pfn_range() installs writable PTEs for the old buffer's pages without taking page references, and the subsequent do_free_pages() returns those pages to the page allocator while the VMA still maps them. This leaves a stale, writable mapping of freed pages: a page-level use-after-free that can be leveraged for local privilege escalation.

Make snd_pcm_mmap_data() participate in the buffer-access scheme introduced for hw_params/hw_free: acquire runtime->buffer_accessing before validating and remapping, and release it afterwards. Buffer reallocation already fails with -EBUSY while accessors are active, and the mmap side now fails with -EBUSY while a reallocation is in progress, so the validate/remap sequence and the check/free sequence can no longer interleave.

A reproducer that turns this race into a stale writable mapping of the freed DMA buffer pages is available on request.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux92ee3c60ec9fe64404dc035e7c41277d74aa26cb < cbc7ec97601d09b74e05e44470fa6b0bcdabf3f5affected
LinuxLinux92ee3c60ec9fe64404dc035e7c41277d74aa26cb < fd137bf8149bc6460f9b7b1fc292025da04cb9eeaffected
LinuxLinux92ee3c60ec9fe64404dc035e7c41277d74aa26cb < 8c1882dfee8f404d118020664b73eb4592172226affected
LinuxLinux92ee3c60ec9fe64404dc035e7c41277d74aa26cb < 9b110a9dcecc59516c77cb3c0caf1f492f75df2daffected
LinuxLinuxa42aa926843acca96c0dfbde2e835b8137f2f092affected
LinuxLinux9cb6c40a6ebe4a0cfc9d6a181958211682cffea9affected
LinuxLinuxfbeb492694ce0441053de57699e1e2b7bc148a69affected
LinuxLinux0f6947f5f5208f6ebd4d76a82a4757e2839a23f8affected
LinuxLinux33061d0fba51d2bf70a2ef9645f703c33fe8e438affected
LinuxLinux0090c13cbbdffd7da079ac56f80373a9a1be0bf8affected
LinuxLinux1bbf82d9f961414d6c76a08f7f843ea068e0ab7baffected
LinuxLinux4.14.279 < 4.15affected
LinuxLinux4.19.243 < 4.20affected
LinuxLinux5.4.193 < 5.5affected
LinuxLinux5.10.109 < 5.11affected
LinuxLinux5.15.32 < 5.16affected
LinuxLinux5.16.18 < 5.17affected
LinuxLinux5.17.1 < 5.18affected
LinuxLinux5.18affected
LinuxLinux0 < 5.18unaffected
LinuxLinux6.12.111 <= 6.12.*unaffected
LinuxLinux6.18.53 <= 6.18.*unaffected
LinuxLinux7.2.7 <= 7.2.*unaffected
LinuxLinux7.3-rc2 <= *unaffected

Weaknesses

References