๐Ÿ” CVE Alert

CVE-2026-74339

UNKNOWN 0.0

ALSA: seq: Clear variable event pointer on read

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: ALSA: seq: Clear variable event pointer on read snd_seq_read() copies a queued variable-length event header to userspace before expanding the payload. Queued variable-length events use SNDRV_SEQ_EXT_CHAINED internally, and data.ext.ptr points at the first extension cell. The read side strips SNDRV_SEQ_EXT_* bits from data.ext.len before the copy, but it leaves data.ext.ptr untouched. A userspace sequencer client can therefore write a direct variable event to itself and read back the extension-cell kernel address from the returned header. Clear the temporary header pointer before copy_to_user(). The original queued event remains unchanged and is still passed to snd_seq_expand_var_event(), so payload expansion keeps using the internal chain.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Aug 15, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 14fe4f75fd5309d6b75f8e840ada88912b374207 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < f29243c211928114f8b906e0a3fee77c236f14c8 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < e0c3edd86414534cfd179fefe45b38c29c01ae7a 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 6b52211eba213c461f68922708a99d8190c1fcd5 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 74ac1ce1f4afdb3b80b6742fa28fb86c8c51d31b 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < c2ac9287e89916da684c2a548798351e63eb59ee 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 705dd6dcbc0ea87351c660c1a6443f85f1001c76
Linux / Linux
2.6.12

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/14fe4f75fd5309d6b75f8e840ada88912b374207 git.kernel.org: https://git.kernel.org/stable/c/f29243c211928114f8b906e0a3fee77c236f14c8 git.kernel.org: https://git.kernel.org/stable/c/e0c3edd86414534cfd179fefe45b38c29c01ae7a git.kernel.org: https://git.kernel.org/stable/c/6b52211eba213c461f68922708a99d8190c1fcd5 git.kernel.org: https://git.kernel.org/stable/c/74ac1ce1f4afdb3b80b6742fa28fb86c8c51d31b git.kernel.org: https://git.kernel.org/stable/c/c2ac9287e89916da684c2a548798351e63eb59ee git.kernel.org: https://git.kernel.org/stable/c/705dd6dcbc0ea87351c660c1a6443f85f1001c76