CVE-2026-98316
Received Received - Intake

Race Condition in Linux Kernel ALSA bcd2000 Driver

Vulnerability report for CVE-2026-98316, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: ALSA: bcd2000: Fix race between rawmidi and disconnect Although we tried to fix the potential UAF issues at USB disconnect on bcd2000 driver, there is still an overlooked case -- namely, when a rawmidi trigger callback has been already running at USB disconnect handling, the in-flight function (e.g. bcd2000_midi_send()) could still access the URB, because the previous URB NULL-check & clearance was considered only for the URB complete callbacks, but not about the parallel rawmidi operations. For addressing the race, this patch introduced a new spinlock that covers each rawmidi operation as well as the rawmidi handling in the complete callback. The URB is cleared with the lock, so it guarantees that the pending rawmidi task already finished or a NULL check is effective.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 16 associated CPEs
Vendor Product Version / Range
Linux Linux 3c00004f134fc819f9d9e202c6a64acde0a1f8d0
Linux Linux 6c07aad8a7c9ef8ebc4d03a964b882123a349a2e
Linux Linux eb482a06791d6168beb8c78cc904ac5a5ed96a55
Linux Linux 7df3194bdb7479cad9199889655a566a2c0c1d1b
Linux Linux b06ebc7fe25a6af4a9f6e4a3d4236a4178ad4b01
Linux Linux 459d3a64766f5ca2f1886daeaf24582831a5f5ab
Linux Linux 9af08677aa57debaca5b57c8045c52a83d3dd376
Linux Linux 5a77febac6faf6da40fbb4555f703eeb91b58130
Linux Linux 6.1.188
Linux Linux 6.6.157
Linux Linux 6.12.109
Linux Linux 6.18.50
Linux Linux 7.2.4
Linux Linux 5.10.270
Linux Linux 5.15.221
Linux Linux 7.3-rc1

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a race condition vulnerability in the Linux kernel's ALSA bcd2000 driver. It occurs when a rawmidi operation is running while the device is being disconnected via USB. The driver fails to properly synchronize access to the URB (USB Request Block), potentially allowing a use-after-free (UAF) scenario where freed memory is accessed.

Detection Guidance

This vulnerability affects the Linux kernel's ALSA bcd2000 driver and is related to a race condition during USB disconnect. Detection requires checking if your system uses the affected driver version. Inspect kernel logs for errors related to bcd2000 or rawmidi operations. Commands like dmesg | grep bcd2000 or lsmod | grep bcd2000 may help identify if the driver is loaded.

Impact Analysis

This could lead to system crashes, data corruption, or privilege escalation if exploited. An attacker with physical access could trigger this by disconnecting the device during active rawmidi operations, causing instability in the kernel.

Mitigation Strategies

Apply the latest kernel update that includes the patch for this vulnerability. If immediate patching is not possible, consider disabling the bcd2000 driver by blacklisting it in your system's module configuration. Restart the affected services or system to ensure changes take effect.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-98316. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart