CVE-2026-23191

HIGH EPSS 1.7%
Published Feb 14, 20264mo ago · Modified Jun 17, 20261w ago
7.0 CVSS 3.1
High
Find Similar
Published Feb 14, 2026 4mo ago
Last Modified Jun 17, 2026 1w ago

Description

In the Linux kernel, the following vulnerability has been resolved: ALSA: aloop: Fix racy access at PCM trigger The PCM trigger callback of aloop driver tries to check the PCM state and stop the stream of the tied substream in the corresponding cable. Since both check and stop operations are performed outside the cable lock, this may result in UAF when a program attempts to trigger frequently while opening/closing the tied stream, as spotted by fuzzers. For addressing the UAF, this patch changes two things: - It covers the most of code in loopback_check_format() with cable->lock spinlock, and add the proper NULL checks. This avoids already some racy accesses. - In addition, now we try to check the state of the capture PCM stream that may be stopped in this function, which was the major pain point leading to UAF.

CVSS Details

Base Score
7.0
Exploitability
1.0
Impact
5.9
Vector string
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector Local
Attack Complexity High
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality High
Integrity High
Availability High

Threat Intelligence

EPSS Exploit Probability
1.7% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Weaknesses 1

CWE-416 Use After Free Memory Safety

Affected Products 10

VendorProductVersionRange
linuxlinux_kernel*≥2.6.37  –  <6.12.70
linuxlinux_kernel*≥6.13  –  <6.18.10
linuxlinux_kernel6.19any
linuxlinux_kernel6.19any
linuxlinux_kernel6.19any
linuxlinux_kernel6.19any
linuxlinux_kernel6.19any
linuxlinux_kernel6.19any
linuxlinux_kernel6.19any
linuxlinux_kernel6.19any

References 3

  • git.kernel.org https://git.kernel.org/stable/c/5727ccf9d19ca414cb76d9b647883822e2789c2e
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/826af7fa62e347464b1b4e0ba2fe19a92438084f
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/bad15420050db1803767e58756114800cce91ea4
    Patch

Remediation

  • git.kernel.org https://git.kernel.org/stable/c/5727ccf9d19ca414cb76d9b647883822e2789c2e
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/826af7fa62e347464b1b4e0ba2fe19a92438084f
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/bad15420050db1803767e58756114800cce91ea4
    Patch