GHSA-877F-C8M6-HQ9R

Vulnerability from github – Published: 2026-10-06 09:31 – Updated: 2026-10-06 09:31
VLAI
Details

In the Linux kernel, the following vulnerability has been resolved:

ALSA: bcd2000: Fix race between rawmidi and disconnect

Although we tried to fix the potential UAF issues at USB disconnect on bcd2000 driver, there is still an overlooked case -- namely, when a rawmidi trigger callback has been already running at USB disconnect handling, the in-flight function (e.g. bcd2000_midi_send()) could still access the URB, because the previous URB NULL-check & clearance was considered only for the URB complete callbacks, but not about the parallel rawmidi operations.

For addressing the race, this patch introduced a new spinlock that covers each rawmidi operation as well as the rawmidi handling in the complete callback. The URB is cleared with the lock, so it guarantees that the pending rawmidi task already finished or a NULL check is effective.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2026-98316"
  ],
  "database_specific": {
    "cwe_ids": [],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2026-10-06T09:18:23Z",
    "severity": null
  },
  "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: bcd2000: Fix race between rawmidi and disconnect\n\nAlthough we tried to fix the potential UAF issues at USB disconnect on\nbcd2000 driver, there is still an overlooked case -- namely, when a\nrawmidi trigger callback has been already running at USB disconnect\nhandling, the in-flight function (e.g. bcd2000_midi_send()) could\nstill access the URB, because the previous URB NULL-check \u0026 clearance\nwas considered only for the URB complete callbacks, but not about the\nparallel rawmidi operations.\n\nFor addressing the race, this patch introduced a new spinlock that\ncovers each rawmidi operation as well as the rawmidi handling in the\ncomplete callback.  The URB is cleared with the lock, so it guarantees\nthat the pending rawmidi task already finished or a NULL check is\neffective.",
  "id": "GHSA-877f-c8m6-hq9r",
  "modified": "2026-10-06T09:31:34Z",
  "published": "2026-10-06T09:31:34Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-98316"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/0a7ecf52cb59ed77ec525deb52c496ea8fba10b1"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/221253723dc58bb901c3f27a7659823e63fc598c"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/3b824930259d54f5047ce6b5c97bd20db2fc2b98"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/812ca56867bec3065c2a27f1ff5ce04e2a8bf4f0"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/9c8b6eff6e7505c128b615d9a1364ef66fa5c18e"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/c83d6b0a65f7b71bbabcc91c045dfbffdff6ae76"
    }
  ],
  "schema_version": "1.4.0",
  "severity": []
}



Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Forecast uses a logistic model when the trend is rising, or an exponential decay model when the trend is falling. Fitted via linearized least squares.

Sightings

Author Source Type Date Other

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or observed by the user.
  • Confirmed: The vulnerability has been validated from an analyst's perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
  • Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
  • Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
  • Not confirmed: The user expressed doubt about the validity of the vulnerability.
  • Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.

Loading…

Loading…

Loading…

Related by attack behaviour

Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.


Loading…