๐Ÿ” CVE Alert

CVE-2026-98086

UNKNOWN 0.0

ALSA: ump: do not touch legacy_rmidi before it exists

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: ALSA: ump: do not touch legacy_rmidi before it exists snd_ump_parse_endpoint() sets ump->parsed on every exit, including error, before the caller attaches the legacy rawmidi device. ump_handle_ep_name_msg() then treats parsed as "legacy_rmidi is live" and calls ump_legacy_set_rawmidi_name(), which snprintf()s into ump->legacy_rmidi->name. If a UMP packet arrives in that window (IRQ path from snd_ump_receive), legacy_rmidi is still NULL (KASAN null-ptr-deref in snprintf). Guard the legacy helpers. parsed only means endpoint info was parsed, not that legacy_rmidi exists.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 25, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
37e0e14128e0685267dc5c037bf655421a6ce2ea < 1c8e01792adf91879322f1ad752f1814de8b7e7d 37e0e14128e0685267dc5c037bf655421a6ce2ea < 228075f31b141395233218712242913125ace4e0 37e0e14128e0685267dc5c037bf655421a6ce2ea < a4cef20cd473e0640fefd38094d4baac0ec76ae3 37e0e14128e0685267dc5c037bf655421a6ce2ea < adeee7187694719890aaffdc14b7e89cfd736f1d
Linux / Linux
6.5

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/1c8e01792adf91879322f1ad752f1814de8b7e7d git.kernel.org: https://git.kernel.org/stable/c/228075f31b141395233218712242913125ace4e0 git.kernel.org: https://git.kernel.org/stable/c/a4cef20cd473e0640fefd38094d4baac0ec76ae3 git.kernel.org: https://git.kernel.org/stable/c/adeee7187694719890aaffdc14b7e89cfd736f1d