CVE-2026-98116 PUBLISHED

ALSA: pcm: Serialize PCM mmap with buffer reallocation to fix page UAF

Assigner: Linux
Reserved: 25.09.2026 Published: 25.09.2026 Updated: 25.09.2026

In the Linux kernel, the following vulnerability has been resolved:

ALSA: pcm: Serialize PCM mmap with buffer reallocation to fix page UAF

snd_pcm_hw_params() and snd_pcm_hw_free() guard buffer reallocation with an mmap_count check performed under the PCM stream lock, but the lock is released long before the buffer is actually freed: snd_pcm_sync_stop(), constraint refinement and do_free_pages() all happen in between. snd_pcm_mmap_data(), on the other hand, takes no lock at all: it validates against the old buffer's state and dma_bytes, remaps its pages into the VMA, and only then increments mmap_count.

A concurrent mmap() can therefore slip in between the check and the free. remap_pfn_range() installs writable PTEs for the old buffer's pages without taking page references, and the subsequent do_free_pages() returns those pages to the page allocator while the VMA still maps them. This leaves a stale, writable mapping of freed pages: a page-level use-after-free that can be leveraged for local privilege escalation.

Make snd_pcm_mmap_data() participate in the buffer-access scheme introduced for hw_params/hw_free: acquire runtime->buffer_accessing before validating and remapping, and release it afterwards. Buffer reallocation already fails with -EBUSY while accessors are active, and the mmap side now fails with -EBUSY while a reallocation is in progress, so the validate/remap sequence and the check/free sequence can no longer interleave.

A reproducer that turns this race into a stale writable mapping of the freed DMA buffer pages is available on request.

Metrics

CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 7.8

AV:L - The bug is triggered by mmap() on a local /dev/snd/pcmCD file descriptor (snd_pcm_mmap -> snd_pcm_mmap_data) racing with SNDRV_PCM_IOCTL_HW_PARAMS/HW_FREE ioctls on the same fd. No remote protocol carries any of the inputs. AC:L - One process controls both sides of the race: one thread calls mmap() and another calls hw_free/hw_params. The window runs from the mmap_count check under the stream lock through snd_pcm_sync_stop and refinement to do_free_pages, and the attacker can retry as often as needed. PR:L - Opening the PCM device node takes ordinary local user access, either the audio group or the udev uaccess ACL given to the logged-in seat user. No capability is checked on the mmap or hw_params/hw_free paths. UI:N - The attacker opens the device, sets hw_params and races the mmap against hw_free entirely through their own syscalls. No other user has to do anything. S:U - This is a local kernel privilege escalation within the same kernel security authority. It crosses no VM or IOMMU boundary. C:H - remap_pfn_range installs PTEs for the old DMA buffer pages without taking page references, and do_free_pages then frees them. The attacker keeps a direct mapping of whatever the page allocator reuses those pages for, such as page tables, cred or slab pages, and can read it. I:H - The stale mapping of the freed buffer pages is writable, which gives direct write access to reallocated kernel pages. This is a page-level UAF that enables privilege escalation, as the fix commit itself states. A:H - Writing through the stale PTEs into pages that have been reallocated corrupts arbitrary kernel memory, which leads to oopses, panics or page-state BUGs.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 92ee3c60ec9fe64404dc035e7c41277d74aa26cb to cbc7ec97601d09b74e05e44470fa6b0bcdabf3f5 (excl.)
  • affected from 92ee3c60ec9fe64404dc035e7c41277d74aa26cb to fd137bf8149bc6460f9b7b1fc292025da04cb9ee (excl.)
  • affected from 92ee3c60ec9fe64404dc035e7c41277d74aa26cb to 8c1882dfee8f404d118020664b73eb4592172226 (excl.)
  • affected from 92ee3c60ec9fe64404dc035e7c41277d74aa26cb to 9b110a9dcecc59516c77cb3c0caf1f492f75df2d (excl.)
  • Version a42aa926843acca96c0dfbde2e835b8137f2f092 is affected
  • Version 9cb6c40a6ebe4a0cfc9d6a181958211682cffea9 is affected
  • Version fbeb492694ce0441053de57699e1e2b7bc148a69 is affected
  • Version 0f6947f5f5208f6ebd4d76a82a4757e2839a23f8 is affected
  • Version 33061d0fba51d2bf70a2ef9645f703c33fe8e438 is affected
  • Version 0090c13cbbdffd7da079ac56f80373a9a1be0bf8 is affected
  • Version 1bbf82d9f961414d6c76a08f7f843ea068e0ab7b is affected
  • affected from 4.14.279 to 4.15 (excl.)
  • affected from 4.19.243 to 4.20 (excl.)
  • affected from 5.4.193 to 5.5 (excl.)
  • affected from 5.10.109 to 5.11 (excl.)
  • affected from 5.15.32 to 5.16 (excl.)
  • affected from 5.16.18 to 5.17 (excl.)
  • affected from 5.17.1 to 5.18 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 5.18 is affected
  • unaffected from 0 to 5.18 (excl.)
  • unaffected from 6.12.111 to 6.12.* (incl.)
  • unaffected from 6.18.53 to 6.18.* (incl.)
  • unaffected from 7.2.7 to 7.2.* (incl.)
  • unaffected from 7.3-rc2 to * (incl.)

References