CVE-2026-90220
CVE CVE-2026-90220EUVD EUVD-2026-81813Veröffentlicht 2026-09-17T16:07:31.000Z
Was das Advisory beschreibt
In the Linux kernel, the following vulnerability has been resolved: ALSA: seq: Don't leak the extension cell pointer in the bounce payload The bounce_error_event() embeds the failed event in the bounce payload by pointing data.ext.ptr at it. When that event is a queued variable-length event, its own data.ext.ptr holds the address of its first extension cell, put there by snd_seq_event_dup(). The payload goes out verbatim through snd_seq_expand_var_event(), so the address reaches userspace. That is the same address commit 705dd6dcbc0e ("ALSA: seq: Clear variable event pointer on read") removed from the event header. The read path still clears it there, just above the call that expands the payload. Embed a sanitised copy instead, treated exactly as snd_seq_read() treats the header. A stack copy is enough because delivery is synchronous and snd_seq_event_dup() copies before returning. An unprivileged client reaches this by setting SNDRV_SEQ_FILTER_BOUNCE, queueing a variable-length event to a port that does not exist and reading the bounce back. Eight bytes on 64-bit, from its own pool.
Quelle: EUVD (ENISA), im Wortlaut der Meldung.
Produkte, die das Advisory nennt
Diese Angaben stammen aus der Meldung selbst, nicht aus einer Prüfung durch uns.
- Linux — Linux 0527a56cb327021cb73167cfddf0e49efa043500; 6.12.97 <6.12.110; efc86691e4d8083d9e380ea95042c2cf679f65fd <59e1592d3c270ff4642d5d6dc55c545306eb0693; patch: 0; patch: 6.12.110; 93d260ce43a81df579c98bee92b91316df9c1c57 <42c3f856d13a91a0d4c302a0c6854813621136db; patch: 6.18.52; efc86691e4d8083d9e380ea95042c2cf679f65fd <6e6e471eef1d5d8cb056c7d364023fe048249204; patch: 7.3-rc1; 7.2; dae23c545eb5a2be3b27a82fd0f611894fb8ab69 <b1e8d40663997aacaa198f37ce6893e07aaba77a; patch: 7.2.6; 6.18.40 <6.18.52; 7.1.5 <7.2
Die genannten Versionen sind die Angabe der Meldung. Patchlage vergleicht keine Versionsnummern und leitet aus ihnen keine Aussage ab — welche Version installiert ist, muss ein Mensch nachsehen.
Im Produktkatalog geführt
Für diese Produkte kann ein Bestand in Patchlage erfasst werden. Ein Advisory dazu erscheint am Morgen danach im Lagebericht.
- Linux — Linux
Betrifft das einen Ihrer Kundenbestände?
Diese Seite kann die Frage nicht beantworten — sie kennt Ihren Bestand nicht. Wer seine Umgebungen erfasst hat, bekommt die Antwort am Morgen nach der Veröffentlichung, zusammen mit einem Absatz, den er unverändert an den Kunden weitergeben kann.
28 Tage testenPatchlage meldet Treffer und Verdachtsfälle. Zu allem anderen sagt dieses System nichts — weder diese Seite noch der Lagebericht behauptet je, dass ein Bestand sicher ist.