CVE-2026-43437 (GCVE-0-2026-43437)
Vulnerability from cvelistv5
Published
2026-05-08 14:22
Modified
2026-08-05 12:27
Summary
In the Linux kernel, the following vulnerability has been resolved: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() In the drain loop, the local variable 'runtime' is reassigned to a linked stream's runtime (runtime = s->runtime at line 2157). After releasing the stream lock at line 2169, the code accesses runtime->no_period_wakeup, runtime->rate, and runtime->buffer_size (lines 2170-2178) — all referencing the linked stream's runtime without any lock or refcount protecting its lifetime. A concurrent close() on the linked stream's fd triggers snd_pcm_release_substream() → snd_pcm_drop() → pcm_release_private() → snd_pcm_unlink() → snd_pcm_detach_substream() → kfree(runtime). No synchronization prevents kfree(runtime) from completing while the drain path dereferences the stale pointer. Fix by caching the needed runtime fields (no_period_wakeup, rate, buffer_size) into local variables while still holding the stream lock, and using the cached values after the lock is released.
Impacted products
Vendor Product Version
Linux Linux Version: f2b3614cefb61ee6046a0aaee503ee37f227d310
Version: f2b3614cefb61ee6046a0aaee503ee37f227d310
Version: f2b3614cefb61ee6046a0aaee503ee37f227d310
Version: f2b3614cefb61ee6046a0aaee503ee37f227d310
Version: f2b3614cefb61ee6046a0aaee503ee37f227d310
Version: f2b3614cefb61ee6046a0aaee503ee37f227d310
Version: f2b3614cefb61ee6046a0aaee503ee37f227d310
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "sound/core/pcm_native.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "9baee36e8c5443411c4629afabafaff8a46a23fd",
              "status": "affected",
              "version": "f2b3614cefb61ee6046a0aaee503ee37f227d310",
              "versionType": "git"
            },
            {
              "lessThan": "fc71f888994569f87d5bee20b1ac6c9c1e3a7a79",
              "status": "affected",
              "version": "f2b3614cefb61ee6046a0aaee503ee37f227d310",
              "versionType": "git"
            },
            {
              "lessThan": "629cf09464cf98670996ea5c191dc9743e6f3f00",
              "status": "affected",
              "version": "f2b3614cefb61ee6046a0aaee503ee37f227d310",
              "versionType": "git"
            },
            {
              "lessThan": "ae8f8d30d334bad5b1b3cdb1eb8a0b771f55e432",
              "status": "affected",
              "version": "f2b3614cefb61ee6046a0aaee503ee37f227d310",
              "versionType": "git"
            },
            {
              "lessThan": "4a758e9a1f5ed722f83c4dd35f867fe811553bcb",
              "status": "affected",
              "version": "f2b3614cefb61ee6046a0aaee503ee37f227d310",
              "versionType": "git"
            },
            {
              "lessThan": "c2f64e05a0587a83ec42dbd6b7a7ded79b2ff694",
              "status": "affected",
              "version": "f2b3614cefb61ee6046a0aaee503ee37f227d310",
              "versionType": "git"
            },
            {
              "lessThan": "9b1dbd69ba6f8f8c69bc7b77c2ce3b9c6ed05ba6",
              "status": "affected",
              "version": "f2b3614cefb61ee6046a0aaee503ee37f227d310",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "sound/core/pcm_native.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "3.0"
            },
            {
              "lessThan": "3.0",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.10.*",
              "status": "unaffected",
              "version": "5.10.253",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.1.*",
              "status": "unaffected",
              "version": "6.1.167",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.6.*",
              "status": "unaffected",
              "version": "6.6.130",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.12.*",
              "status": "unaffected",
              "version": "6.12.78",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.18.*",
              "status": "unaffected",
              "version": "6.18.19",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.19.*",
              "status": "unaffected",
              "version": "6.19.9",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "7.0",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.10.253",
                  "versionStartIncluding": "3.0",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.1.167",
                  "versionStartIncluding": "3.0",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.6.130",
                  "versionStartIncluding": "3.0",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.12.78",
                  "versionStartIncluding": "3.0",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.18.19",
                  "versionStartIncluding": "3.0",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.19.9",
                  "versionStartIncluding": "3.0",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.0",
                  "versionStartIncluding": "3.0",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain()\n\nIn the drain loop, the local variable \u0027runtime\u0027 is reassigned to a\nlinked stream\u0027s runtime (runtime = s-\u003eruntime at line 2157).  After\nreleasing the stream lock at line 2169, the code accesses\nruntime-\u003eno_period_wakeup, runtime-\u003erate, and runtime-\u003ebuffer_size\n(lines 2170-2178) \u2014 all referencing the linked stream\u0027s runtime without\nany lock or refcount protecting its lifetime.\n\nA concurrent close() on the linked stream\u0027s fd triggers\nsnd_pcm_release_substream() \u2192 snd_pcm_drop() \u2192 pcm_release_private()\n\u2192 snd_pcm_unlink() \u2192 snd_pcm_detach_substream() \u2192 kfree(runtime).\nNo synchronization prevents kfree(runtime) from completing while the\ndrain path dereferences the stale pointer.\n\nFix by caching the needed runtime fields (no_period_wakeup, rate,\nbuffer_size) into local variables while still holding the stream lock,\nand using the cached values after the lock is released."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:L - The vulnerable path is reached through ALSA PCM character-device operations, specifically userspace `ioctl(SNDRV_PCM_IOCTL_DRAIN)` after opening and linking PCM fds. It is not reachable by network packets or adjacent/physical input alone.\nAC:L - The attacker can control both sides of the race by opening linked PCM streams and concurrently issuing drain on one fd while closing the linked fd. The required stream state and timing are attacker-orchestrated local operations.\nPR:L - No kernel capability check gates `SNDRV_PCM_IOCTL_LINK` or `SNDRV_PCM_IOCTL_DRAIN`, but the attacker needs local access to usable ALSA PCM device files. This is basic local user/device access rather than real root/admin privilege.\nUI:N - Exploitation does not require a victim user to open media or perform any action. The attacker can trigger the vulnerable ioctl and concurrent close directly.\nS:U - The affected component is the local kernel ALSA PCM subsystem, and exploitation impacts the same kernel security authority. There is no VM, IOMMU, or other cross-scope boundary involved.\nC:H - This is a kernel heap use-after-free of `struct snd_pcm_runtime`; under the required scoring guidance, UAFs are treated as capable of enabling high-impact information disclosure. Freed runtime contents can be reclaimed or influenced before stale dereferences.\nI:H - Although the immediate stale accesses are runtime field dereferences, this is kernel heap memory corruption involving freed ALSA runtime/waitqueue state. Following the required UAF guidance and higher-severity rule, it is scored as potentially enabling arbitrary write or control-flow corruption.\nA:H - The UAF can dereference freed kernel memory during the drain wait path and can lead to kernel oops, panic, or hang. It is attacker-repeatable from local userspace once PCM device access is available."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T12:27:55.761Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/9baee36e8c5443411c4629afabafaff8a46a23fd"
        },
        {
          "url": "https://git.kernel.org/stable/c/fc71f888994569f87d5bee20b1ac6c9c1e3a7a79"
        },
        {
          "url": "https://git.kernel.org/stable/c/629cf09464cf98670996ea5c191dc9743e6f3f00"
        },
        {
          "url": "https://git.kernel.org/stable/c/ae8f8d30d334bad5b1b3cdb1eb8a0b771f55e432"
        },
        {
          "url": "https://git.kernel.org/stable/c/4a758e9a1f5ed722f83c4dd35f867fe811553bcb"
        },
        {
          "url": "https://git.kernel.org/stable/c/c2f64e05a0587a83ec42dbd6b7a7ded79b2ff694"
        },
        {
          "url": "https://git.kernel.org/stable/c/9b1dbd69ba6f8f8c69bc7b77c2ce3b9c6ed05ba6"
        }
      ],
      "title": "ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain()",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2026-43437",
    "datePublished": "2026-05-08T14:22:07.314Z",
    "dateReserved": "2026-05-01T14:12:56.009Z",
    "dateUpdated": "2026-08-05T12:27:55.761Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…