PT-2026-52288 · Linux · Linux
Published
2026-06-25
·
Updated
2026-06-25
·
CVE-2026-53192
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
ALSA: timer: Fix UAF at snd timer user params()
At releasing a timer object, e.g. when a userspace timer
(CONFIG SND UTIMER) gets closed and snd timer free() is called, it
tries to detach the timer instances and release the resources.
However, it's still possible that other in-flight tasks are holding
the timer instance where the to-be-deleted timer object is associated,
and this may lead to racy accesses.
Fortunately, most of ioctls dealing with the timer instance list
already have the protection with register mutex, and this also avoids
such races. But, SNDRV TIMER IOCTL PARAMS isn't protected, hence the
concurrent ioctl may lead to use-after-free.
This patch just adds the guard with register mutex to protect
snd timer user params() for covering the code path as a quick
workaround. It's no hot-path but rather a rarely issued ioctl, so the
performance penalty doesn't matter.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux