« Volver al listado

CVE-2026-90220

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

ALSA: seq: Don't leak the extension cell pointer in the bounce payload

The bounce_error_event() embeds the failed event in the bounce payload by pointing data.ext.ptr at it. When that event is a queued variable-length event, its own data.ext.ptr holds the address of its first extension cell, put there by snd_seq_event_dup(). The payload goes out verbatim through snd_seq_expand_var_event(), so the address reaches userspace.

That is the same address commit 705dd6dcbc0e ("ALSA: seq: Clear variable event pointer on read") removed from the event header. The read path still clears it there, just above the call that expands the payload.

Leer descripción completaMostrar menos

Embed a sanitised copy instead, treated exactly as snd_seq_read() treats the header. A stack copy is enough because delivery is synchronous and snd_seq_event_dup() copies before returning.

An unprivileged client reaches this by setting SNDRV_SEQ_FILTER_BOUNCE, queueing a variable-length event to a port that does not exist and reading the bounce back. Eight bytes on 64-bit, from its own pool.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-90220",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "93d260ce43a81df579c98bee92b91316df9c1c57",
              "lessThan": "42c3f856d13a91a0d4c302a0c6854813621136db",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "dae23c545eb5a2be3b27a82fd0f611894fb8ab69",
              "lessThan": "b1e8d40663997aacaa198f37ce6893e07aaba77a",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "efc86691e4d8083d9e380ea95042c2cf679f65fd",
              "lessThan": "6e6e471eef1d5d8cb056c7d364023fe048249204",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "efc86691e4d8083d9e380ea95042c2cf679f65fd",
              "lessThan": "59e1592d3c270ff4642d5d6dc55c545306eb0693",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "0527a56cb327021cb73167cfddf0e49efa043500",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "6.12.97",
              "lessThan": "6.12.110",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.18.40",
              "lessThan": "6.18.52",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "7.1.5",
              "lessThan": "7.2",
              "versionType": "semver"
            }
          ],
          "programFiles": [
            "sound/core/seq/seq_clientmgr.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "7.2"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "7.2",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.12.110",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.52",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.6",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "sound/core/seq/seq_clientmgr.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-17T17:17:17.440",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/42c3f856d13a91a0d4c302a0c6854813621136db",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/59e1592d3c270ff4642d5d6dc55c545306eb0693",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/6e6e471eef1d5d8cb056c7d364023fe048249204",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/b1e8d40663997aacaa198f37ce6893e07aaba77a",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: seq: Don't leak the extension cell pointer in the bounce payload\n\nThe bounce_error_event() embeds the failed event in the bounce payload\nby pointing data.ext.ptr at it.  When that event is a queued\nvariable-length event, its own data.ext.ptr holds the address of its\nfirst extension cell, put there by snd_seq_event_dup().  The payload\ngoes out verbatim through snd_seq_expand_var_event(), so the address\nreaches userspace.\n\nThat is the same address commit 705dd6dcbc0e (\"ALSA: seq: Clear\nvariable event pointer on read\") removed from the event header.  The\nread path still clears it there, just above the call that expands the\npayload.\n\nEmbed a sanitised copy instead, treated exactly as snd_seq_read()\ntreats the header.  A stack copy is enough because delivery is\nsynchronous and snd_seq_event_dup() copies before returning.\n\nAn unprivileged client reaches this by setting SNDRV_SEQ_FILTER_BOUNCE,\nqueueing a variable-length event to a port that does not exist and\nreading the bounce back.  Eight bytes on 64-bit, from its own pool."
    }
  ],
  "lastModified": "2026-09-17T17:17:17.440",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}