{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2026-43437",
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "state": "PUBLISHED",
        "assignerShortName": "Linux",
        "dateReserved": "2026-05-01T14:12:56.009Z",
        "datePublished": "2026-05-08T14:22:07.314Z",
        "dateUpdated": "2026-09-02T12:49:31.385Z"
    },
    "containers": {
        "cna": {
            "providerMetadata": {
                "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
                "shortName": "Linux",
                "dateUpdated": "2026-09-02T12:49:31.385Z"
            },
            "descriptions": [
                {
                    "lang": "en",
                    "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain()\n\nIn the drain loop, the local variable 'runtime' is reassigned to a\nlinked stream's runtime (runtime = s->runtime at line 2157).  After\nreleasing the stream lock at line 2169, the code accesses\nruntime->no_period_wakeup, runtime->rate, and runtime->buffer_size\n(lines 2170-2178) — all referencing the linked stream's runtime without\nany lock or refcount protecting its lifetime.\n\nA concurrent close() on the linked stream's fd triggers\nsnd_pcm_release_substream() → snd_pcm_drop() → pcm_release_private()\n→ snd_pcm_unlink() → snd_pcm_detach_substream() → kfree(runtime).\nNo synchronization prevents kfree(runtime) from completing while the\ndrain path dereferences the stale pointer.\n\nFix by caching the needed runtime fields (no_period_wakeup, rate,\nbuffer_size) into local variables while still holding the stream lock,\nand using the cached values after the lock is released."
                }
            ],
            "metrics": [
                {
                    "cvssV3_1": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH"
                    },
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "AV:L - The vulnerable path is reached through ALSA PCM character-device operations, specifically userspace `ioctl(SNDRV_PCM_IOCTL_DRAIN)` after opening and linking PCM fds. It is not reachable by network packets or adjacent/physical input alone.\nAC:L - The attacker can control both sides of the race by opening linked PCM streams and concurrently issuing drain on one fd while closing the linked fd. The required stream state and timing are attacker-orchestrated local operations.\nPR:L - No kernel capability check gates `SNDRV_PCM_IOCTL_LINK` or `SNDRV_PCM_IOCTL_DRAIN`, but the attacker needs local access to usable ALSA PCM device files. This is basic local user/device access rather than real root/admin privilege.\nUI:N - Exploitation does not require a victim user to open media or perform any action. The attacker can trigger the vulnerable ioctl and concurrent close directly.\nS:U - The affected component is the local kernel ALSA PCM subsystem, and exploitation impacts the same kernel security authority. There is no VM, IOMMU, or other cross-scope boundary involved.\nC:H - This is a kernel heap use-after-free of `struct snd_pcm_runtime`; under the required scoring guidance, UAFs are treated as capable of enabling high-impact information disclosure. Freed runtime contents can be reclaimed or influenced before stale dereferences.\nI:H - Although the immediate stale accesses are runtime field dereferences, this is kernel heap memory corruption involving freed ALSA runtime/waitqueue state. Following the required UAF guidance and higher-severity rule, it is scored as potentially enabling arbitrary write or control-flow corruption.\nA:H - The UAF can dereference freed kernel memory during the drain wait path and can lead to kernel oops, panic, or hang. It is attacker-repeatable from local userspace once PCM device access is available."
                        }
                    ]
                }
            ],
            "affected": [
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "unaffected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "sound/core/pcm_native.c"
                    ],
                    "versions": [
                        {
                            "version": "f2b3614cefb61ee6046a0aaee503ee37f227d310",
                            "lessThan": "9baee36e8c5443411c4629afabafaff8a46a23fd",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "f2b3614cefb61ee6046a0aaee503ee37f227d310",
                            "lessThan": "f2cb2e0d27fb925c73a78f0ce7d6dbf68d3747c1",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "f2b3614cefb61ee6046a0aaee503ee37f227d310",
                            "lessThan": "fc71f888994569f87d5bee20b1ac6c9c1e3a7a79",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "f2b3614cefb61ee6046a0aaee503ee37f227d310",
                            "lessThan": "629cf09464cf98670996ea5c191dc9743e6f3f00",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "f2b3614cefb61ee6046a0aaee503ee37f227d310",
                            "lessThan": "ae8f8d30d334bad5b1b3cdb1eb8a0b771f55e432",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "f2b3614cefb61ee6046a0aaee503ee37f227d310",
                            "lessThan": "4a758e9a1f5ed722f83c4dd35f867fe811553bcb",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "f2b3614cefb61ee6046a0aaee503ee37f227d310",
                            "lessThan": "c2f64e05a0587a83ec42dbd6b7a7ded79b2ff694",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "f2b3614cefb61ee6046a0aaee503ee37f227d310",
                            "lessThan": "9b1dbd69ba6f8f8c69bc7b77c2ce3b9c6ed05ba6",
                            "status": "affected",
                            "versionType": "git"
                        }
                    ]
                },
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "affected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "sound/core/pcm_native.c"
                    ],
                    "versions": [
                        {
                            "version": "3.0",
                            "status": "affected"
                        },
                        {
                            "version": "0",
                            "lessThan": "3.0",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "5.10.253",
                            "lessThanOrEqual": "5.10.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "5.15.220",
                            "lessThanOrEqual": "5.15.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.1.167",
                            "lessThanOrEqual": "6.1.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.6.130",
                            "lessThanOrEqual": "6.6.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.12.78",
                            "lessThanOrEqual": "6.12.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.18.19",
                            "lessThanOrEqual": "6.18.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.19.9",
                            "lessThanOrEqual": "6.19.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "7.0",
                            "lessThanOrEqual": "*",
                            "status": "unaffected",
                            "versionType": "original_commit_for_fix"
                        }
                    ]
                }
            ],
            "cpeApplicability": [
                {
                    "nodes": [
                        {
                            "operator": "OR",
                            "negate": false,
                            "cpeMatch": [
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "3.0",
                                    "versionEndExcluding": "5.10.253"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "3.0",
                                    "versionEndExcluding": "5.15.220"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "3.0",
                                    "versionEndExcluding": "6.1.167"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "3.0",
                                    "versionEndExcluding": "6.6.130"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "3.0",
                                    "versionEndExcluding": "6.12.78"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "3.0",
                                    "versionEndExcluding": "6.18.19"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "3.0",
                                    "versionEndExcluding": "6.19.9"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "3.0",
                                    "versionEndExcluding": "7.0"
                                }
                            ]
                        }
                    ]
                }
            ],
            "references": [
                {
                    "url": "https://git.kernel.org/stable/c/9baee36e8c5443411c4629afabafaff8a46a23fd"
                },
                {
                    "url": "https://git.kernel.org/stable/c/f2cb2e0d27fb925c73a78f0ce7d6dbf68d3747c1"
                },
                {
                    "url": "https://git.kernel.org/stable/c/fc71f888994569f87d5bee20b1ac6c9c1e3a7a79"
                },
                {
                    "url": "https://git.kernel.org/stable/c/629cf09464cf98670996ea5c191dc9743e6f3f00"
                },
                {
                    "url": "https://git.kernel.org/stable/c/ae8f8d30d334bad5b1b3cdb1eb8a0b771f55e432"
                },
                {
                    "url": "https://git.kernel.org/stable/c/4a758e9a1f5ed722f83c4dd35f867fe811553bcb"
                },
                {
                    "url": "https://git.kernel.org/stable/c/c2f64e05a0587a83ec42dbd6b7a7ded79b2ff694"
                },
                {
                    "url": "https://git.kernel.org/stable/c/9b1dbd69ba6f8f8c69bc7b77c2ce3b9c6ed05ba6"
                }
            ],
            "title": "ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain()",
            "x_generator": {
                "engine": "bippy-1.2.0"
            }
        }
    }
}