CVE-2026-98116
CVE CVE-2026-98116EUVD EUVD-2026-86947Veröffentlicht 2026-09-25T10:36:01.000ZZuletzt geändert 2026-09-25T14:42:08.000ZCVSS 7.8
Was das Advisory beschreibt
In the Linux kernel, the following vulnerability has been resolved: ALSA: pcm: Serialize PCM mmap with buffer reallocation to fix page UAF snd_pcm_hw_params() and snd_pcm_hw_free() guard buffer reallocation with an mmap_count check performed under the PCM stream lock, but the lock is released long before the buffer is actually freed: snd_pcm_sync_stop(), constraint refinement and do_free_pages() all happen in between. snd_pcm_mmap_data(), on the other hand, takes no lock at all: it validates against the old buffer's state and dma_bytes, remaps its pages into the VMA, and only then increments mmap_count. A concurrent mmap() can therefore slip in between the check and the free. remap_pfn_range() installs writable PTEs for the old buffer's pages without taking page references, and the subsequent do_free_pages() returns those pages to the page allocator while the VMA still maps them. This leaves a stale, writable mapping of freed pages: a page-level use-after-free that can be leveraged for local privilege escalation. Make snd_pcm_mmap_data() participate in the buffer-access scheme introduced for hw_params/hw_free: acquire runtime->buffer_accessing before validating and remapping, and release it afterwards. Buffer reallocation already fails with -EBUSY while accessors are active, and the mmap side now fails with -EBUSY while a reallocation is in progress, so the validate/remap sequence and the check/free sequence can no longer interleave. A reproducer that turns this race into a stale writable mapping of the freed DMA buffer pages is available on request.
Quelle: EUVD (ENISA), im Wortlaut der Meldung.
Produkte, die das Advisory nennt
Diese Angaben stammen aus der Meldung selbst, nicht aus einer Prüfung durch uns.
- Linux — Linux 92ee3c60ec9fe64404dc035e7c41277d74aa26cb <9b110a9dcecc59516c77cb3c0caf1f492f75df2d; patch: 7.3-rc2; patch: 6.12.111; 4.19.243 <4.20; 5.15.32 <5.16; 5.4.193 <5.5; 4.14.279 <4.15; fbeb492694ce0441053de57699e1e2b7bc148a69; 5.10.109 <5.11; 92ee3c60ec9fe64404dc035e7c41277d74aa26cb <8c1882dfee8f404d118020664b73eb4592172226; 33061d0fba51d2bf70a2ef9645f703c33fe8e438; patch: 6.18.53; 92ee3c60ec9fe64404dc035e7c41277d74aa26cb <fd137bf8149bc6460f9b7b1fc292025da04cb9ee; 5.17.1 <5.18; 0f6947f5f5208f6ebd4d76a82a4757e2839a23f8; patch: 7.2.7; 9cb6c40a6ebe4a0cfc9d6a181958211682cffea9; a42aa926843acca96c0dfbde2e835b8137f2f092; 1bbf82d9f961414d6c76a08f7f843ea068e0ab7b; 92ee3c60ec9fe64404dc035e7c41277d74aa26cb <cbc7ec97601d09b74e05e44470fa6b0bcdabf3f5; 5.18; 5.16.18 <5.17; 0090c13cbbdffd7da079ac56f80373a9a1be0bf8; patch: 0
Die genannten Versionen sind die Angabe der Meldung. Patchlage vergleicht keine Versionsnummern und leitet aus ihnen keine Aussage ab — welche Version installiert ist, muss ein Mensch nachsehen.
Im Produktkatalog geführt
Für diese Produkte kann ein Bestand in Patchlage erfasst werden. Ein Advisory dazu erscheint am Morgen danach im Lagebericht.
- Linux — Linux
Betrifft das einen Ihrer Kundenbestände?
Diese Seite kann die Frage nicht beantworten — sie kennt Ihren Bestand nicht. Wer seine Umgebungen erfasst hat, bekommt die Antwort am Morgen nach der Veröffentlichung, zusammen mit einem Absatz, den er unverändert an den Kunden weitergeben kann.
28 Tage testenPatchlage meldet Treffer und Verdachtsfälle. Zu allem anderen sagt dieses System nichts — weder diese Seite noch der Lagebericht behauptet je, dass ein Bestand sicher ist.