« Volver al listado

CVE-2026-98116

Estado: En análisisAlta (7.8)—

In the Linux kernel, the following vulnerability has been resolved:

ALSA: pcm: Serialize PCM mmap with buffer reallocation to fix page UAF

snd_pcm_hw_params() and snd_pcm_hw_free() guard buffer reallocation with an mmap_count check performed under the PCM stream lock, but the lock is released long before the buffer is actually freed: snd_pcm_sync_stop(), constraint refinement and do_free_pages() all happen in between. snd_pcm_mmap_data(), on the other hand, takes no lock at all: it validates against the old buffer's state and dma_bytes, remaps its pages into the VMA, and only then increments mmap_count.

Leer descripción completaMostrar menos

A concurrent mmap() can therefore slip in between the check and the free. remap_pfn_range() installs writable PTEs for the old buffer's pages without taking page references, and the subsequent do_free_pages() returns those pages to the page allocator while the VMA still maps them. This leaves a stale, writable mapping of freed pages: a page-level use-after-free that can be leveraged for local privilege escalation.

Make snd_pcm_mmap_data() participate in the buffer-access scheme introduced for hw_params/hw_free: acquire runtime->buffer_accessing before validating and remapping, and release it afterwards. Buffer reallocation already fails with -EBUSY while accessors are active, and the mmap side now fails with -EBUSY while a reallocation is in progress, so the validate/remap sequence and the check/free sequence can no longer interleave.

A reproducer that turns this race into a stale writable mapping of the freed DMA buffer pages is available on request.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

UAF de páginas en kernel con acceso local; permite escalada de privilegios mediante MMU race condition en ALSA PCM buffer reallocation con permisos locales (AV:L, PR:L).

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-98116",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "33061d0fba51d2bf70a2ef9645f703c33fe8e438",
              "lessThan": "e6cdd2a0470d64073349a970dc1691433804b271",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "92ee3c60ec9fe64404dc035e7c41277d74aa26cb",
              "lessThan": "9857a75714bb5df4781e4d8b1a1753b1e17bf07a",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "92ee3c60ec9fe64404dc035e7c41277d74aa26cb",
              "lessThan": "cbadf2575d25e7dcc0d4da2717817ae569fbc99b",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "92ee3c60ec9fe64404dc035e7c41277d74aa26cb",
              "lessThan": "cbc7ec97601d09b74e05e44470fa6b0bcdabf3f5",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "92ee3c60ec9fe64404dc035e7c41277d74aa26cb",
              "lessThan": "fd137bf8149bc6460f9b7b1fc292025da04cb9ee",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "92ee3c60ec9fe64404dc035e7c41277d74aa26cb",
              "lessThan": "8c1882dfee8f404d118020664b73eb4592172226",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "92ee3c60ec9fe64404dc035e7c41277d74aa26cb",
              "lessThan": "9b110a9dcecc59516c77cb3c0caf1f492f75df2d",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "a42aa926843acca96c0dfbde2e835b8137f2f092",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "9cb6c40a6ebe4a0cfc9d6a181958211682cffea9",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "fbeb492694ce0441053de57699e1e2b7bc148a69",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "0f6947f5f5208f6ebd4d76a82a4757e2839a23f8",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "0090c13cbbdffd7da079ac56f80373a9a1be0bf8",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "1bbf82d9f961414d6c76a08f7f843ea068e0ab7b",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "5.15.32",
              "lessThan": "5.15.222",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "4.14.279",
              "lessThan": "4.15",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "4.19.243",
              "lessThan": "4.20",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "5.4.193",
              "lessThan": "5.5",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "5.10.109",
              "lessThan": "5.11",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "5.16.18",
              "lessThan": "5.17",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "5.17.1",
              "lessThan": "5.18",
              "versionType": "semver"
            }
          ],
          "programFiles": [
            "sound/core/pcm_native.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.18"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "5.18",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.15.222",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.189",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.158",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.111",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.53",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.7",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "sound/core/pcm_native.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-25T11:17:42.780",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/8c1882dfee8f404d118020664b73eb4592172226",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/9857a75714bb5df4781e4d8b1a1753b1e17bf07a",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/9b110a9dcecc59516c77cb3c0caf1f492f75df2d",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/cbadf2575d25e7dcc0d4da2717817ae569fbc99b",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/cbc7ec97601d09b74e05e44470fa6b0bcdabf3f5",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/e6cdd2a0470d64073349a970dc1691433804b271",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/fd137bf8149bc6460f9b7b1fc292025da04cb9ee",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Undergoing Analysis",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: pcm: Serialize PCM mmap with buffer reallocation to fix page UAF\n\nsnd_pcm_hw_params() and snd_pcm_hw_free() guard buffer reallocation\nwith an mmap_count check performed under the PCM stream lock, but the\nlock is released long before the buffer is actually freed:\nsnd_pcm_sync_stop(), constraint refinement and do_free_pages() all\nhappen in between.  snd_pcm_mmap_data(), on the other hand, takes no\nlock at all: it validates against the old buffer's state and\ndma_bytes, remaps its pages into the VMA, and only then increments\nmmap_count.\n\nA concurrent mmap() can therefore slip in between the check and the\nfree.  remap_pfn_range() installs writable PTEs for the old buffer's\npages without taking page references, and the subsequent\ndo_free_pages() returns those pages to the page allocator while the\nVMA still maps them.  This leaves a stale, writable mapping of freed\npages: a page-level use-after-free that can be leveraged for local\nprivilege escalation.\n\nMake snd_pcm_mmap_data() participate in the buffer-access scheme\nintroduced for hw_params/hw_free: acquire runtime->buffer_accessing\nbefore validating and remapping, and release it afterwards.  Buffer\nreallocation already fails with -EBUSY while accessors are active,\nand the mmap side now fails with -EBUSY while a reallocation is in\nprogress, so the validate/remap sequence and the check/free sequence\ncan no longer interleave.\n\nA reproducer that turns this race into a stale writable mapping of\nthe freed DMA buffer pages is available on request."
    }
  ],
  "lastModified": "2026-10-03T11:18:33.517",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}