« Back to list

CVE-2026-80628

Status: ReceivedHigh (7.8)—

In the Linux kernel, the following vulnerability has been resolved:

ALSA: seq: oss: Serialize readq reset state with q->lock

snd_seq_oss_readq_clear() resets qlen, head, and tail without q->lock even though the normal reader and producer paths serialize the same ring state under that spinlock. A reset can therefore race snd_seq_oss_readq_free() or snd_seq_oss_readq_put_event() and leave stale records in the queue, drop freshly queued ones, or report the wrong readiness after wakeup. KCSAN reports a data race between snd_seq_oss_readq_clear() and snd_seq_oss_readq_free().

Take q->lock while clearing the ring and resetting input_time. Factor the enqueue logic into a caller-locked helper so snd_seq_oss_readq_put_timestamp() updates its suppression state under the same lock instead of racing the reset path.

Read full descriptionShow less

The buggy scenario involves two paths, with each column showing the order within that path:

KCSAN reports:

value changed: 0x00000001 -> 0x00000000

Technical details traces, logs and code from the original report
reset path:                      locked readq updater:
1. snd_seq_oss_reset() or        1. A reader or callback producer
   release reaches                  takes q->lock on the same queue.
   snd_seq_oss_readq_clear().
2. snd_seq_oss_readq_clear()     2. The updater tests or modifies
   resets qlen, head, tail,         qlen, head, and tail.
   and input_time.
3. snd_seq_oss_readq_clear()     3. The updater completes its
   wakes sleepers on                read-modify-write sequence.
   q->midi_sleep.
4. Without q->lock, the reset    4. The resulting ring state drives
   can overlap the locked           later reads and readiness.
   update.

BUG: KCSAN: data-race in snd_seq_oss_readq_clear /
snd_seq_oss_readq_free

write to 0xffff8881069fe608 of 4 bytes by task 120516 on cpu 0:
  snd_seq_oss_readq_free+0x6c/0x80
  snd_seq_oss_read+0xcb/0x250
  odev_read+0x38/0x60
  vfs_read+0xff/0x600
  ksys_read+0xb4/0x140
  __x64_sys_read+0x46/0x60
  do_syscall_64+0xbb/0x2f0
  entry_SYSCALL_64_after_hwframe+0x77/0x7f

read to 0xffff8881069fe608 of 4 bytes by task 120517 on cpu 1:
  snd_seq_oss_readq_clear+0x1f/0x90
  snd_seq_oss_reset+0xa7/0xf0
  snd_seq_oss_ioctl+0x6f6/0x7e0
  odev_ioctl+0x56/0xc0
  __x64_sys_ioctl+0xd1/0x120
  do_syscall_64+0xbb/0x2f0
  entry_SYSCALL_64_after_hwframe+0x77/0x7f

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

🎯 ATT&CK techniques

How this vulnerability is exploited and what the attacker gains, in MITRE ATT&CK terms.

Vulnerabilidad local de race condition en kernel Linux (AV:L, PR:L). Permite escalada de privilegios corruptiendo estado de cola de audio ALSA; impacto: DoS y corrupción de datos en evento de audio.

Inferred by our analysis agent from the official description, CVSS vector and CWE, and checked by a supervisor. May contain errors.

🛡️ ATT&CK mitigations that cover these techniques

Affected technologies (1)

⚠ AI-inferred from the description — NVD hasn't analyzed this CVE yet, these aren't verified CPEs.

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2026-80628",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
              "lessThan": "287d506d4e0865918cec82bb1361f283a08c979b",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
              "lessThan": "43e10709b1ba288bcbabb9b9cb6e518b2a5d8506",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2",
              "lessThan": "49ce92d207820f588b0406add82f053decfbe5d9",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "sound/core/seq/oss/seq_oss_readq.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "2.6.12"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "2.6.12",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.18.40",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.1.5",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "sound/core/seq/oss/seq_oss_readq.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-08-28T08:16:47.007",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/287d506d4e0865918cec82bb1361f283a08c979b",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/43e10709b1ba288bcbabb9b9cb6e518b2a5d8506",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/49ce92d207820f588b0406add82f053decfbe5d9",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: seq: oss: Serialize readq reset state with q->lock\n\nsnd_seq_oss_readq_clear() resets qlen, head, and tail without\nq->lock even though the normal reader and producer paths serialize the\nsame ring state under that spinlock. A reset can therefore race\nsnd_seq_oss_readq_free() or snd_seq_oss_readq_put_event() and leave\nstale records in the queue, drop freshly queued ones, or report the\nwrong readiness after wakeup. KCSAN reports a data race between\nsnd_seq_oss_readq_clear() and snd_seq_oss_readq_free().\n\nTake q->lock while clearing the ring and resetting input_time. Factor\nthe enqueue logic into a caller-locked helper so\nsnd_seq_oss_readq_put_timestamp() updates its suppression state under\nthe same lock instead of racing the reset path.\n\nThe buggy scenario involves two paths, with each column showing the\norder within that path:\n\nreset path:                      locked readq updater:\n1. snd_seq_oss_reset() or        1. A reader or callback producer\n   release reaches                  takes q->lock on the same queue.\n   snd_seq_oss_readq_clear().\n2. snd_seq_oss_readq_clear()     2. The updater tests or modifies\n   resets qlen, head, tail,         qlen, head, and tail.\n   and input_time.\n3. snd_seq_oss_readq_clear()     3. The updater completes its\n   wakes sleepers on                read-modify-write sequence.\n   q->midi_sleep.\n4. Without q->lock, the reset    4. The resulting ring state drives\n   can overlap the locked           later reads and readiness.\n   update.\n\nKCSAN reports:\n\nBUG: KCSAN: data-race in snd_seq_oss_readq_clear /\nsnd_seq_oss_readq_free\n\nwrite to 0xffff8881069fe608 of 4 bytes by task 120516 on cpu 0:\n  snd_seq_oss_readq_free+0x6c/0x80\n  snd_seq_oss_read+0xcb/0x250\n  odev_read+0x38/0x60\n  vfs_read+0xff/0x600\n  ksys_read+0xb4/0x140\n  __x64_sys_read+0x46/0x60\n  do_syscall_64+0xbb/0x2f0\n  entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\nread to 0xffff8881069fe608 of 4 bytes by task 120517 on cpu 1:\n  snd_seq_oss_readq_clear+0x1f/0x90\n  snd_seq_oss_reset+0xa7/0xf0\n  snd_seq_oss_ioctl+0x6f6/0x7e0\n  odev_ioctl+0x56/0xc0\n  __x64_sys_ioctl+0xd1/0x120\n  do_syscall_64+0xbb/0x2f0\n  entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\nvalue changed: 0x00000001 -> 0x00000000"
    }
  ],
  "lastModified": "2026-08-29T07:16:46.900",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}