PT-2026-8199 · Linux+3 · Linux Kernel+3

Published

2026-01-01

·

Updated

2026-05-26

·

CVE-2026-23191

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A race condition exists in the ALSA aloop driver’s PCM trigger callback. The callback attempts to check the PCM state and stop the stream of a tied substream without proper locking, potentially leading to a use-after-free (UAF) condition when a program frequently triggers while opening or closing the tied stream. The issue arises from performing checks and stop operations outside the cable lock. The fix involves covering code within loopback check format() with the cable->lock spinlock and adding null checks, as well as verifying the state of the capture PCM stream.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Use After Free

Weakness Enumeration

Related Identifiers

ALSA-2026:6153
ALSA-2026:6632
ALSA-2026:9131
ALSA-2026:9135
CVE-2026-23191
ECHO-F6BC-CADA-385A
OESA-2026-1569
OESA-2026-1760
OPENSUSE-SU-2026:20416-1
RHSA-2026:13734
RHSA-2026:13932
RHSA-2026:13936
RHSA-2026:14137
RHSA-2026:14230
RHSA-2026:14301
RHSA-2026:14869
RHSA-2026:14925
RHSA-2026:19521
RHSA-2026:6153
RHSA-2026:6632
RHSA-2026:9131
RHSA-2026:9135
SUSE-SU-2026:0928-1
SUSE-SU-2026:0961-1
SUSE-SU-2026:0962-1
SUSE-SU-2026:0984-1
SUSE-SU-2026:1003-1
SUSE-SU-2026:1041-1
SUSE-SU-2026:1077-1
SUSE-SU-2026:1078-1
SUSE-SU-2026:1081-1
SUSE-SU-2026:1130-1
SUSE-SU-2026:1131-1
SUSE-SU-2026:1464-1
SUSE-SU-2026:1535-1
SUSE-SU-2026:1537-1
SUSE-SU-2026:1560-1
SUSE-SU-2026:1578-1
SUSE-SU-2026:1584-1
SUSE-SU-2026:1592-1
SUSE-SU-2026:1611-1
SUSE-SU-2026:1621-1
SUSE-SU-2026:1622-1
SUSE-SU-2026:1629-1
SUSE-SU-2026:1630-1
SUSE-SU-2026:20667-1
SUSE-SU-2026:20720-1
SUSE-SU-2026:20838-1
SUSE-SU-2026:20845-1
SUSE-SU-2026:20876-1
SUSE-SU-2026:20931-1
SUSE-SU-2026:21284-1
USN-8278-1
USN-8278-2
USN-8289-1
USN-8289-2
USN-8296-1
USN-8296-2

Affected Products

Linuxmint
Linux Kernel
Rocky Linux
Ubuntu