๐Ÿ” CVE Alert

CVE-2026-46090

HIGH 7.8

ALSA: aloop: Fix peer runtime UAF during format-change stop

CVSS Score
7.8
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: ALSA: aloop: Fix peer runtime UAF during format-change stop loopback_check_format() may stop the capture side when playback starts with parameters that no longer match a running capture stream. Commit 826af7fa62e3 ("ALSA: aloop: Fix racy access at PCM trigger") moved the peer lookup under cable->lock, but the actual snd_pcm_stop() still runs after dropping that lock. A concurrent close can clear the capture entry from cable->streams[] and detach or free its runtime while the playback trigger path still holds a stale peer substream pointer. Keep a per-cable count of in-flight peer stops before dropping cable->lock, and make free_cable() wait for those stops before detaching the runtime. This preserves the existing behavior while making the peer runtime lifetime explicit.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published May 27, 2026
Last Updated May 30, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new high vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Linux / Linux
597603d615d2b19a9e451d8cfac24372856a522d < 03f52a9c170431e8f10e156b9dc0dae80b3e9198 597603d615d2b19a9e451d8cfac24372856a522d < bdd9503c3d222d2735b56c7a8b4422ccf3de6e5c 597603d615d2b19a9e451d8cfac24372856a522d < 5d45e34bf001344e2966dabca1897561bbc9e913 597603d615d2b19a9e451d8cfac24372856a522d < e5c33cdc6f402eab8abd36ecf436b22c9d3a8aff
Linux / Linux
2.6.37

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/03f52a9c170431e8f10e156b9dc0dae80b3e9198 git.kernel.org: https://git.kernel.org/stable/c/bdd9503c3d222d2735b56c7a8b4422ccf3de6e5c git.kernel.org: https://git.kernel.org/stable/c/5d45e34bf001344e2966dabca1897561bbc9e913 git.kernel.org: https://git.kernel.org/stable/c/e5c33cdc6f402eab8abd36ecf436b22c9d3a8aff