๐Ÿ” CVE Alert

CVE-2026-98314

UNKNOWN 0.0

ALSA: pcm: set timer->private_data before registering the PCM timer

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: ALSA: pcm: set timer->private_data before registering the PCM timer snd_pcm_timer_init() calls snd_device_register() to link the new struct snd_timer into the global timer list while it still carries hw.c_resolution = snd_pcm_timer_resolution (and hw.start/hw.stop), and only afterwards sets timer->private_data = substream. Once the timer is on the list under register_mutex, a concurrent reader can already reach it through the same mutex and invoke these callbacks. /proc/asound/timers does this via c_resolution(), and snd_timer_open()+snd_timer_start() reach start()/stop() the same way. All three dereference timer->private_data, which for this brief window is NULL, giving a NULL-pointer dereference: substream = timer->private_data; return substream->runtime ? ... // substream is NULL Move the private_data/private_free assignment before snd_device_register() so the timer is never visible on the list without its private_data set. On the snd_device_register() failure path, private_free() (snd_pcm_timer_free()) can now run, but it only does substream->timer = NULL, which is already NULL at that point since substream->timer is set to the new timer just once, after a successful registration -- so the failure path stays safe.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Oct 6, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 27f167e117eca310661fbcbacb352ea08face067 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 555d168bd98daa46daccc68c908201388c834293 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 8c869d5cf5affb20994bdbb60e7d46d65c91b55f 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 686c7a6af1eea8d2a919303e4c6bbec3de79dbdc 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < e1eee8f16628f8b6bcae0a366fd6a2dd65e71edd 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < d63f5a9f8121fb43c798056d7dd34c58f47185d7 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 0b349249d572633d7c8cdeb917623d1676a2b7c3 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 1e713f9bb2ac583521f06b0eb4e22440b1e3d078
Linux / Linux
2.6.12

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/27f167e117eca310661fbcbacb352ea08face067 git.kernel.org: https://git.kernel.org/stable/c/555d168bd98daa46daccc68c908201388c834293 git.kernel.org: https://git.kernel.org/stable/c/8c869d5cf5affb20994bdbb60e7d46d65c91b55f git.kernel.org: https://git.kernel.org/stable/c/686c7a6af1eea8d2a919303e4c6bbec3de79dbdc git.kernel.org: https://git.kernel.org/stable/c/e1eee8f16628f8b6bcae0a366fd6a2dd65e71edd git.kernel.org: https://git.kernel.org/stable/c/d63f5a9f8121fb43c798056d7dd34c58f47185d7 git.kernel.org: https://git.kernel.org/stable/c/0b349249d572633d7c8cdeb917623d1676a2b7c3 git.kernel.org: https://git.kernel.org/stable/c/1e713f9bb2ac583521f06b0eb4e22440b1e3d078