Linux vulnerability

In the Linux kernel, the following vulnerability has been resolved: ALSA: aloop: Fix peer runtime UAF during format-change stop loopback_check_format() may stop the capture side when playback starts with parameters that no longer match a running capture stream. Commit 826af7fa62e3 ("ALSA: aloop: Fix racy access at PCM trigger") moved the peer lookup under cable->lock, but the actual snd_pcm_stop() still runs after dropping that lock. A concurrent close can clear the capture entry from cable->streams[] and detach or free its runtime while the playback trigger path still holds a stale peer substream pointer. Keep a per-cable count of in-flight peer stops before dropping cable->lock, and make free_cable() wait for those stops before detaching the runtime. This preserves the existing behavior while making the peer runtime lifetime explicit.

Published 27 May 2026Updated 14 Sep 202625 sources
CVSS 7.8

What happened

In the Linux kernel, the following vulnerability has been resolved: ALSA: aloop: Fix peer runtime UAF during format-change stop loopback_check_format() may stop the capture side when playback starts with parameters that no longer match a running capture stream. Commit 826af7fa62e3 ("ALSA: aloop: Fix racy access at PCM trigger") moved the peer lookup under cable->lock, but the actual snd_pcm_stop() still runs after dropping that lock. A concurrent close can clear the capture entry from cable->streams[] and detach or free its runtime while the playback trigger path still holds a stale peer substream pointer. Keep a per-cable count of in-flight peer stops before dropping cable->lock, and make free_cable() wait for those stops before detaching the runtime. This preserves the existing behavior while making the peer runtime lifetime explicit.

Affected versions

Linux: 597603d615d2b19a9e451d8cfac24372856a522d through before 83bd62fa9620ac98d5d694bde14c50f98c8e7189 (git); 597603d615d2b19a9e451d8cfac24372856a522d through before 345c24b2bcf0923dfae1ab41497351c68214ff76 (git); 597603d615d2b19a9e451d8cfac24372856a522d through before 3727a3541788412c393eec236ad228d72efe19c7 (git); 597603d615d2b19a9e451d8cfac24372856a522d through before d258cdce50ff3e02392917258e81a0ce9555c327 (git); 597603d615d2b19a9e451d8cfac24372856a522d through before 03f52a9c170431e8f10e156b9dc0dae80b3e9198 (git); 597603d615d2b19a9e451d8cfac24372856a522d through before bdd9503c3d222d2735b56c7a8b4422ccf3de6e5c (git); 597603d615d2b19a9e451d8cfac24372856a522d through before 5d45e34bf001344e2966dabca1897561bbc9e913 (git); 597603d615d2b19a9e451d8cfac24372856a522d through before e5c33cdc6f402eab8abd36ecf436b22c9d3a8aff (git); 2.6.37 Fixed: See vendor advisory.

Why it matters

Review the vendor advisory and exposure of the affected product to determine operational impact.

Detection & mitigation

  • Apply vendor-provided updates or mitigations.
  • Review affected product exposure and access logs.

Public PoC references

No public PoC reference has passed the current publication threshold.