{"api_version":"1","generated_at":"2026-08-15T20:27:07+00:00","cve":"CVE-2026-74504","urls":{"html":"https://cve.report/CVE-2026-74504","api":"https://cve.report/api/cve/CVE-2026-74504.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-74504","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-74504"},"summary":{"title":"ALSA: seq: Fix division by zero in initialize_timer()","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: seq: Fix division by zero in initialize_timer()\n\nA userspace-driven ALSA timer (SND_UTIMER) lets an unprivileged user set\nthe backing snd_timer's hardware resolution to an arbitrary 64-bit value\nvia SNDRV_TIMER_IOCTL_CREATE. snd_utimer_create() only rejects zero.\n\nWhen such a timer is bound to a sequencer queue, initialize_timer()\ncomputes the tick period as\n\n\ttmr->ticks = 1000000000 / (r * freq);\n\nwhere r is that user-controlled resolution and freq is the sequencer\nupdate rate in Hz, clamped to MIN_FREQUENCY..MAX_FREQUENCY (10..6250).\nA resolution of 2^63 makes the 64-bit product r * freq wrap to zero for\nany even freq, including DEFAULT_FREQUENCY (1000), so the division faults\nwith a divide-by-zero.\n\nThe division runs under tmr->lock with interrupts disabled, so the oops\nleaves the spinlock held and hangs the CPU. It is reachable by an\nunprivileged user with access to /dev/snd/timer and /dev/snd/seq.\n\n  Oops: divide error: 0000 [#1] SMP KASAN PTI\n  CPU: 7 UID: 1000 PID: 456 Comm: alsa_seq_utimer Not tainted 7.2.0-rc4+\n  RIP: 0010:initialize_timer.constprop.0+0x20a/0x2d0\n   snd_seq_timer_start+0x15e/0x2b0\n   snd_seq_control_queue+0x56f/0xba0\n   snd_seq_write+0x3e0/0x730\n\nReject an overflowing product with check_mul_overflow() and fall back to\na single tick, which also avoids feeding a wrapped-but-nonzero divisor\n(e.g. 2^63 * 1000 mod 2^64 == 0, or other resolutions wrapping to a small\nvalue) into the period computation.","state":"PUBLISHED","assigner":"Linux","published_at":"2026-08-15 13:17:55","updated_at":"2026-08-15 13:17:55"},"problem_types":[],"metrics":[],"references":[{"url":"https://git.kernel.org/stable/c/5260e195c53e898a4a76527d4bb2178f31795e78","name":"https://git.kernel.org/stable/c/5260e195c53e898a4a76527d4bb2178f31795e78","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/42c6543ff27ea280334244458d4f52ec7133cc05","name":"https://git.kernel.org/stable/c/42c6543ff27ea280334244458d4f52ec7133cc05","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/21e19688433452dfbbbe6b2bb670dea6eb92f0f6","name":"https://git.kernel.org/stable/c/21e19688433452dfbbbe6b2bb670dea6eb92f0f6","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/d0e19932875746118e298b4c974f3b2d4aeb16fc","name":"https://git.kernel.org/stable/c/d0e19932875746118e298b4c974f3b2d4aeb16fc","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-74504","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-74504","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 37745918e0e7575bc40f38da93a99b9fa6406224 d0e19932875746118e298b4c974f3b2d4aeb16fc git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 37745918e0e7575bc40f38da93a99b9fa6406224 5260e195c53e898a4a76527d4bb2178f31795e78 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 37745918e0e7575bc40f38da93a99b9fa6406224 42c6543ff27ea280334244458d4f52ec7133cc05 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 37745918e0e7575bc40f38da93a99b9fa6406224 21e19688433452dfbbbe6b2bb670dea6eb92f0f6 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 6.12","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.12 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.12.103 6.12.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.18.44 6.18.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.1.8 7.1.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.2-rc6 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["sound/core/seq/seq_timer.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"d0e19932875746118e298b4c974f3b2d4aeb16fc","status":"affected","version":"37745918e0e7575bc40f38da93a99b9fa6406224","versionType":"git"},{"lessThan":"5260e195c53e898a4a76527d4bb2178f31795e78","status":"affected","version":"37745918e0e7575bc40f38da93a99b9fa6406224","versionType":"git"},{"lessThan":"42c6543ff27ea280334244458d4f52ec7133cc05","status":"affected","version":"37745918e0e7575bc40f38da93a99b9fa6406224","versionType":"git"},{"lessThan":"21e19688433452dfbbbe6b2bb670dea6eb92f0f6","status":"affected","version":"37745918e0e7575bc40f38da93a99b9fa6406224","versionType":"git"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["sound/core/seq/seq_timer.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"6.12"},{"lessThan":"6.12","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"6.12.*","status":"unaffected","version":"6.12.103","versionType":"semver"},{"lessThanOrEqual":"6.18.*","status":"unaffected","version":"6.18.44","versionType":"semver"},{"lessThanOrEqual":"7.1.*","status":"unaffected","version":"7.1.8","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.2-rc6","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.12.103","versionStartIncluding":"6.12","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.18.44","versionStartIncluding":"6.12","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.1.8","versionStartIncluding":"6.12","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2-rc6","versionStartIncluding":"6.12","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: seq: Fix division by zero in initialize_timer()\n\nA userspace-driven ALSA timer (SND_UTIMER) lets an unprivileged user set\nthe backing snd_timer's hardware resolution to an arbitrary 64-bit value\nvia SNDRV_TIMER_IOCTL_CREATE. snd_utimer_create() only rejects zero.\n\nWhen such a timer is bound to a sequencer queue, initialize_timer()\ncomputes the tick period as\n\n\ttmr->ticks = 1000000000 / (r * freq);\n\nwhere r is that user-controlled resolution and freq is the sequencer\nupdate rate in Hz, clamped to MIN_FREQUENCY..MAX_FREQUENCY (10..6250).\nA resolution of 2^63 makes the 64-bit product r * freq wrap to zero for\nany even freq, including DEFAULT_FREQUENCY (1000), so the division faults\nwith a divide-by-zero.\n\nThe division runs under tmr->lock with interrupts disabled, so the oops\nleaves the spinlock held and hangs the CPU. It is reachable by an\nunprivileged user with access to /dev/snd/timer and /dev/snd/seq.\n\n  Oops: divide error: 0000 [#1] SMP KASAN PTI\n  CPU: 7 UID: 1000 PID: 456 Comm: alsa_seq_utimer Not tainted 7.2.0-rc4+\n  RIP: 0010:initialize_timer.constprop.0+0x20a/0x2d0\n   snd_seq_timer_start+0x15e/0x2b0\n   snd_seq_control_queue+0x56f/0xba0\n   snd_seq_write+0x3e0/0x730\n\nReject an overflowing product with check_mul_overflow() and fall back to\na single tick, which also avoids feeding a wrapped-but-nonzero divisor\n(e.g. 2^63 * 1000 mod 2^64 == 0, or other resolutions wrapping to a small\nvalue) into the period computation."}],"providerMetadata":{"dateUpdated":"2026-08-15T12:27:28.829Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/d0e19932875746118e298b4c974f3b2d4aeb16fc"},{"url":"https://git.kernel.org/stable/c/5260e195c53e898a4a76527d4bb2178f31795e78"},{"url":"https://git.kernel.org/stable/c/42c6543ff27ea280334244458d4f52ec7133cc05"},{"url":"https://git.kernel.org/stable/c/21e19688433452dfbbbe6b2bb670dea6eb92f0f6"}],"title":"ALSA: seq: Fix division by zero in initialize_timer()","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-74504","datePublished":"2026-08-15T12:27:28.829Z","dateReserved":"2026-08-15T05:44:03.908Z","dateUpdated":"2026-08-15T12:27:28.829Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-08-15 13:17:55","lastModifiedDate":"2026-08-15 13:17:55","problem_types":[],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"74504","Ordinal":"1","Title":"ALSA: seq: Fix division by zero in initialize_timer()","CVE":"CVE-2026-74504","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"74504","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: seq: Fix division by zero in initialize_timer()\n\nA userspace-driven ALSA timer (SND_UTIMER) lets an unprivileged user set\nthe backing snd_timer's hardware resolution to an arbitrary 64-bit value\nvia SNDRV_TIMER_IOCTL_CREATE. snd_utimer_create() only rejects zero.\n\nWhen such a timer is bound to a sequencer queue, initialize_timer()\ncomputes the tick period as\n\n\ttmr->ticks = 1000000000 / (r * freq);\n\nwhere r is that user-controlled resolution and freq is the sequencer\nupdate rate in Hz, clamped to MIN_FREQUENCY..MAX_FREQUENCY (10..6250).\nA resolution of 2^63 makes the 64-bit product r * freq wrap to zero for\nany even freq, including DEFAULT_FREQUENCY (1000), so the division faults\nwith a divide-by-zero.\n\nThe division runs under tmr->lock with interrupts disabled, so the oops\nleaves the spinlock held and hangs the CPU. It is reachable by an\nunprivileged user with access to /dev/snd/timer and /dev/snd/seq.\n\n  Oops: divide error: 0000 [#1] SMP KASAN PTI\n  CPU: 7 UID: 1000 PID: 456 Comm: alsa_seq_utimer Not tainted 7.2.0-rc4+\n  RIP: 0010:initialize_timer.constprop.0+0x20a/0x2d0\n   snd_seq_timer_start+0x15e/0x2b0\n   snd_seq_control_queue+0x56f/0xba0\n   snd_seq_write+0x3e0/0x730\n\nReject an overflowing product with check_mul_overflow() and fall back to\na single tick, which also avoids feeding a wrapped-but-nonzero divisor\n(e.g. 2^63 * 1000 mod 2^64 == 0, or other resolutions wrapping to a small\nvalue) into the period computation.","Type":"Description","Title":"ALSA: seq: Fix division by zero in initialize_timer()"}]}}}