CVE-2026-98314
Received
Received - Intake
Null Pointer Dereference in Linux Kernel ALSA PCM Timer
Vulnerability report for CVE-2026-98314, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-10-06
Last updated on: 2026-10-06
Assigner: kernel.org
Description
Description
In the Linux kernel, the following vulnerability has been resolved:
ALSA: pcm: set timer->private_data before registering the PCM timer
snd_pcm_timer_init() calls snd_device_register() to link the new
struct snd_timer into the global timer list while it still carries
hw.c_resolution = snd_pcm_timer_resolution (and hw.start/hw.stop),
and only afterwards sets timer->private_data = substream.
Once the timer is on the list under register_mutex, a concurrent
reader can already reach it through the same mutex and invoke these
callbacks. /proc/asound/timers does this via c_resolution(), and
snd_timer_open()+snd_timer_start() reach start()/stop() the same way.
All three dereference timer->private_data, which for this brief
window is NULL, giving a NULL-pointer dereference:
substream = timer->private_data;
return substream->runtime ? ... // substream is NULL
Move the private_data/private_free assignment before
snd_device_register() so the timer is never visible on the list
without its private_data set. On the snd_device_register() failure
path, private_free() (snd_pcm_timer_free()) can now run, but it only
does substream->timer = NULL, which is already NULL at that point
since substream->timer is set to the new timer just once, after a
successful registration -- so the failure path stays safe.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| Linux | Linux | 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 |
| Linux | Linux | 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 |
| Linux | Linux | 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 |
| Linux | Linux | 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 |
| Linux | Linux | 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 |
| Linux | Linux | 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 |
| Linux | Linux | 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 |
| Linux | Linux | 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 |
| Linux | Linux | 2.6.12 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |