Zero Day Monitor
DashboardVulnerabilitiesTrendingZero-DaysNews
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
738 articles · 106207 vulns · 36/50 feeds (7d)
← Back to list
7.0
CVE-2026-23191

In the Linux kernel, the following vulnerability has been resolved: ALSA: aloop: Fix racy access at PCM trigger The PCM trigger callback of aloop driver tries to check the PCM state and stop the str

Description

In the Linux kernel, the following vulnerability has been resolved: ALSA: aloop: Fix racy access at PCM trigger The PCM trigger callback of aloop driver tries to check the PCM state and stop the stream of the tied substream in the corresponding cable. Since both check and stop operations are performed outside the cable lock, this may result in UAF when a program attempts to trigger frequently while opening/closing the tied stream, as spotted by fuzzers. For addressing the UAF, this patch changes two things: - It covers the most of code in loopback_check_format() with cable->lock spinlock, and add the proper NULL checks. This avoids already some racy accesses. - In addition, now we try to check the state of the capture PCM stream that may be stopped in this function, which was the major pain point leading to UAF.

Affected Products

VendorProductVersions
linuxlinux_kernel< 6.12.70, < 6.18.10

References

  • https://git.kernel.org/stable/c/5727ccf9d19ca414cb76d9b647883822e2789c2e(Patch)
  • https://git.kernel.org/stable/c/826af7fa62e347464b1b4e0ba2fe19a92438084f(Patch)
  • https://git.kernel.org/stable/c/bad15420050db1803767e58756114800cce91ea4(Patch)

Related News (2 articles)

Tier A
Microsoft MSRC4d ago
CVE-2026-23191 ALSA: aloop: Fix racy access at PCM trigger
→ No new info (linked only)
Tier B
CERT-FR5d ago
Multiples vulnérabilités dans le noyau Linux de SUSE (20 mars 2026)
→ No new info (linked only)
CVSS 3.17.0 HIGH
VectorCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited❌ No
CWECWE-416
Published2/14/2026
Last enriched4h ago
Trending Score17
Source articles2
Independent2
Info Completeness8/14
Missing: epss, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Pin to Dashboard

Verification

State: verified
Confidence: 100%