CVE-2026-53192
ALSA: timer: Fix UAF at snd_timer_user_params()
Vexday Risk Score
3Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS —EPSS 0.2%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
25 jun 2026Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
In the Linux kernel, the following vulnerability has been resolved:
ALSA: timer: Fix UAF at snd_timer_user_params()
At releasing a timer object, e.g. when a userspace timer
(CONFIG_SND_UTIMER) gets closed and snd_timer_free() is called, it
tries to detach the timer instances and release the resources.
However, it's still possible that other in-flight tasks are holding
the timer instance where the to-be-deleted timer object is associated,
and this may lead to racy accesses.
Fortunately, most of ioctls dealing with the timer instance list
already have the protection with register_mutex, and this also avoids
such races. But, SNDRV_TIMER_IOCTL_PARAMS isn't protected, hence the
concurrent ioctl may lead to use-after-free.
This patch just adds the guard with register_mutex to protect
snd_timer_user_params() for covering the code path as a quick
workaround. It's no hot-path but rather a rarely issued ioctl, so the
performance penalty doesn't matter.
Productos afectados
Linux · Linux¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →Referencias
https://git.kernel.org/stable/c/053a401b592be424fea9d57c789f66cd5d8cec11https://git.kernel.org/stable/c/117743d62e1225e208568a3ffc2c07214f1347cbhttps://git.kernel.org/stable/c/306427adf9b97e29e5958cb9cf3096c6151fc9ffhttps://git.kernel.org/stable/c/38034d04d4a75bbca01df2b313ced0bcd0fa3242https://git.kernel.org/stable/c/3d39da65b5c422c5e5afb7d5651b0698d060a827https://git.kernel.org/stable/c/92ad2d7f80cad43b046f093e808e11fe919d304ahttps://git.kernel.org/stable/c/b2214914e461d0466548a52dfe4f4ee8ce362276https://git.kernel.org/stable/c/e2331730175f74169046d2af8db1b47243df7c7a