{"api_version":"1","generated_at":"2026-09-25T13:40:16+00:00","cve":"CVE-2026-98116","urls":{"html":"https://cve.report/CVE-2026-98116","api":"https://cve.report/api/cve/CVE-2026-98116.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-98116","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-98116"},"summary":{"title":"ALSA: pcm: Serialize PCM mmap with buffer reallocation to fix page UAF","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: pcm: Serialize PCM mmap with buffer reallocation to fix page UAF\n\nsnd_pcm_hw_params() and snd_pcm_hw_free() guard buffer reallocation\nwith an mmap_count check performed under the PCM stream lock, but the\nlock is released long before the buffer is actually freed:\nsnd_pcm_sync_stop(), constraint refinement and do_free_pages() all\nhappen in between.  snd_pcm_mmap_data(), on the other hand, takes no\nlock at all: it validates against the old buffer's state and\ndma_bytes, remaps its pages into the VMA, and only then increments\nmmap_count.\n\nA concurrent mmap() can therefore slip in between the check and the\nfree.  remap_pfn_range() installs writable PTEs for the old buffer's\npages without taking page references, and the subsequent\ndo_free_pages() returns those pages to the page allocator while the\nVMA still maps them.  This leaves a stale, writable mapping of freed\npages: a page-level use-after-free that can be leveraged for local\nprivilege escalation.\n\nMake snd_pcm_mmap_data() participate in the buffer-access scheme\nintroduced for hw_params/hw_free: acquire runtime->buffer_accessing\nbefore validating and remapping, and release it afterwards.  Buffer\nreallocation already fails with -EBUSY while accessors are active,\nand the mmap side now fails with -EBUSY while a reallocation is in\nprogress, so the validate/remap sequence and the check/free sequence\ncan no longer interleave.\n\nA reproducer that turns this race into a stale writable mapping of\nthe freed DMA buffer pages is available on request.","state":"PUBLISHED","assigner":"Linux","published_at":"2026-09-25 11:17:42","updated_at":"2026-09-25 11:17:42"},"problem_types":[],"metrics":[],"references":[{"url":"https://git.kernel.org/stable/c/cbc7ec97601d09b74e05e44470fa6b0bcdabf3f5","name":"https://git.kernel.org/stable/c/cbc7ec97601d09b74e05e44470fa6b0bcdabf3f5","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/fd137bf8149bc6460f9b7b1fc292025da04cb9ee","name":"https://git.kernel.org/stable/c/fd137bf8149bc6460f9b7b1fc292025da04cb9ee","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/8c1882dfee8f404d118020664b73eb4592172226","name":"https://git.kernel.org/stable/c/8c1882dfee8f404d118020664b73eb4592172226","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/9b110a9dcecc59516c77cb3c0caf1f492f75df2d","name":"https://git.kernel.org/stable/c/9b110a9dcecc59516c77cb3c0caf1f492f75df2d","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-98116","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-98116","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 92ee3c60ec9fe64404dc035e7c41277d74aa26cb cbc7ec97601d09b74e05e44470fa6b0bcdabf3f5 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 92ee3c60ec9fe64404dc035e7c41277d74aa26cb fd137bf8149bc6460f9b7b1fc292025da04cb9ee git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 92ee3c60ec9fe64404dc035e7c41277d74aa26cb 8c1882dfee8f404d118020664b73eb4592172226 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 92ee3c60ec9fe64404dc035e7c41277d74aa26cb 9b110a9dcecc59516c77cb3c0caf1f492f75df2d git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected a42aa926843acca96c0dfbde2e835b8137f2f092 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 9cb6c40a6ebe4a0cfc9d6a181958211682cffea9 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected fbeb492694ce0441053de57699e1e2b7bc148a69 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 0f6947f5f5208f6ebd4d76a82a4757e2839a23f8 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 33061d0fba51d2bf70a2ef9645f703c33fe8e438 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 0090c13cbbdffd7da079ac56f80373a9a1be0bf8 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 1bbf82d9f961414d6c76a08f7f843ea068e0ab7b git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 4.14.279 4.15 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 4.19.243 4.20 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 5.4.193 5.5 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 5.10.109 5.11 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 5.15.32 5.16 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 5.16.18 5.17 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 5.17.1 5.18 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 5.18","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 5.18 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.12.111 6.12.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.18.53 6.18.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.2.7 7.2.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.3-rc2 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["sound/core/pcm_native.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"cbc7ec97601d09b74e05e44470fa6b0bcdabf3f5","status":"affected","version":"92ee3c60ec9fe64404dc035e7c41277d74aa26cb","versionType":"git"},{"lessThan":"fd137bf8149bc6460f9b7b1fc292025da04cb9ee","status":"affected","version":"92ee3c60ec9fe64404dc035e7c41277d74aa26cb","versionType":"git"},{"lessThan":"8c1882dfee8f404d118020664b73eb4592172226","status":"affected","version":"92ee3c60ec9fe64404dc035e7c41277d74aa26cb","versionType":"git"},{"lessThan":"9b110a9dcecc59516c77cb3c0caf1f492f75df2d","status":"affected","version":"92ee3c60ec9fe64404dc035e7c41277d74aa26cb","versionType":"git"},{"status":"affected","version":"a42aa926843acca96c0dfbde2e835b8137f2f092","versionType":"git"},{"status":"affected","version":"9cb6c40a6ebe4a0cfc9d6a181958211682cffea9","versionType":"git"},{"status":"affected","version":"fbeb492694ce0441053de57699e1e2b7bc148a69","versionType":"git"},{"status":"affected","version":"0f6947f5f5208f6ebd4d76a82a4757e2839a23f8","versionType":"git"},{"status":"affected","version":"33061d0fba51d2bf70a2ef9645f703c33fe8e438","versionType":"git"},{"status":"affected","version":"0090c13cbbdffd7da079ac56f80373a9a1be0bf8","versionType":"git"},{"status":"affected","version":"1bbf82d9f961414d6c76a08f7f843ea068e0ab7b","versionType":"git"},{"lessThan":"4.15","status":"affected","version":"4.14.279","versionType":"semver"},{"lessThan":"4.20","status":"affected","version":"4.19.243","versionType":"semver"},{"lessThan":"5.5","status":"affected","version":"5.4.193","versionType":"semver"},{"lessThan":"5.11","status":"affected","version":"5.10.109","versionType":"semver"},{"lessThan":"5.16","status":"affected","version":"5.15.32","versionType":"semver"},{"lessThan":"5.17","status":"affected","version":"5.16.18","versionType":"semver"},{"lessThan":"5.18","status":"affected","version":"5.17.1","versionType":"semver"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["sound/core/pcm_native.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"5.18"},{"lessThan":"5.18","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"6.12.*","status":"unaffected","version":"6.12.111","versionType":"semver"},{"lessThanOrEqual":"6.18.*","status":"unaffected","version":"6.18.53","versionType":"semver"},{"lessThanOrEqual":"7.2.*","status":"unaffected","version":"7.2.7","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.3-rc2","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.12.111","versionStartIncluding":"5.18","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.18.53","versionStartIncluding":"5.18","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2.7","versionStartIncluding":"5.18","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.3-rc2","versionStartIncluding":"5.18","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.14.279","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.19.243","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.4.193","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.10.109","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.15.32","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.16.18","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.17.1","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: pcm: Serialize PCM mmap with buffer reallocation to fix page UAF\n\nsnd_pcm_hw_params() and snd_pcm_hw_free() guard buffer reallocation\nwith an mmap_count check performed under the PCM stream lock, but the\nlock is released long before the buffer is actually freed:\nsnd_pcm_sync_stop(), constraint refinement and do_free_pages() all\nhappen in between.  snd_pcm_mmap_data(), on the other hand, takes no\nlock at all: it validates against the old buffer's state and\ndma_bytes, remaps its pages into the VMA, and only then increments\nmmap_count.\n\nA concurrent mmap() can therefore slip in between the check and the\nfree.  remap_pfn_range() installs writable PTEs for the old buffer's\npages without taking page references, and the subsequent\ndo_free_pages() returns those pages to the page allocator while the\nVMA still maps them.  This leaves a stale, writable mapping of freed\npages: a page-level use-after-free that can be leveraged for local\nprivilege escalation.\n\nMake snd_pcm_mmap_data() participate in the buffer-access scheme\nintroduced for hw_params/hw_free: acquire runtime->buffer_accessing\nbefore validating and remapping, and release it afterwards.  Buffer\nreallocation already fails with -EBUSY while accessors are active,\nand the mmap side now fails with -EBUSY while a reallocation is in\nprogress, so the validate/remap sequence and the check/free sequence\ncan no longer interleave.\n\nA reproducer that turns this race into a stale writable mapping of\nthe freed DMA buffer pages is available on request."}],"providerMetadata":{"dateUpdated":"2026-09-25T10:36:01.723Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/cbc7ec97601d09b74e05e44470fa6b0bcdabf3f5"},{"url":"https://git.kernel.org/stable/c/fd137bf8149bc6460f9b7b1fc292025da04cb9ee"},{"url":"https://git.kernel.org/stable/c/8c1882dfee8f404d118020664b73eb4592172226"},{"url":"https://git.kernel.org/stable/c/9b110a9dcecc59516c77cb3c0caf1f492f75df2d"}],"title":"ALSA: pcm: Serialize PCM mmap with buffer reallocation to fix page UAF","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-98116","datePublished":"2026-09-25T10:36:01.723Z","dateReserved":"2026-09-25T10:25:14.317Z","dateUpdated":"2026-09-25T10:36:01.723Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-25 11:17:42","lastModifiedDate":"2026-09-25 11:17:42","problem_types":[],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"98116","Ordinal":"1","Title":"ALSA: pcm: Serialize PCM mmap with buffer reallocation to fix pa","CVE":"CVE-2026-98116","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"98116","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: pcm: Serialize PCM mmap with buffer reallocation to fix page UAF\n\nsnd_pcm_hw_params() and snd_pcm_hw_free() guard buffer reallocation\nwith an mmap_count check performed under the PCM stream lock, but the\nlock is released long before the buffer is actually freed:\nsnd_pcm_sync_stop(), constraint refinement and do_free_pages() all\nhappen in between.  snd_pcm_mmap_data(), on the other hand, takes no\nlock at all: it validates against the old buffer's state and\ndma_bytes, remaps its pages into the VMA, and only then increments\nmmap_count.\n\nA concurrent mmap() can therefore slip in between the check and the\nfree.  remap_pfn_range() installs writable PTEs for the old buffer's\npages without taking page references, and the subsequent\ndo_free_pages() returns those pages to the page allocator while the\nVMA still maps them.  This leaves a stale, writable mapping of freed\npages: a page-level use-after-free that can be leveraged for local\nprivilege escalation.\n\nMake snd_pcm_mmap_data() participate in the buffer-access scheme\nintroduced for hw_params/hw_free: acquire runtime->buffer_accessing\nbefore validating and remapping, and release it afterwards.  Buffer\nreallocation already fails with -EBUSY while accessors are active,\nand the mmap side now fails with -EBUSY while a reallocation is in\nprogress, so the validate/remap sequence and the check/free sequence\ncan no longer interleave.\n\nA reproducer that turns this race into a stale writable mapping of\nthe freed DMA buffer pages is available on request.","Type":"Description","Title":"ALSA: pcm: Serialize PCM mmap with buffer reallocation to fix pa"}]}}}