Answer in brief
CVE-2026-97931 records a High severity (CVSS 7.0) vulnerability in ALSA: us122l: Prevent write upgrades for read mappings. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 7.0. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=030a07e441296c372f946cd4065b5d831d8dc40c <64a87950239867682cde128020e1a47088295e5c || >=030a07e441296c372f946cd4065b5d831d8dc40c <d9c537b14f4982f17b103e3a2cfeee4bee6bc026 || >=030a07e441296c372f946cd4065b5d831d8dc40c <0eb9dd4774af0ac4d1fd105ef2b0a1f6cec06f2f || >=030a07e441296c372f946cd4065b5d831d8dc40c <71c610aeb1770302ac9c9e0b9a4ecd37f1311928 | 64a87950239867682cde128020e1a47088295e5c, d9c537b14f4982f17b103e3a2cfeee4bee6bc026, 0eb9dd4774af0ac4d1fd105ef2b0a1f6cec06f2f, 71c610aeb1770302ac9c9e0b9a4ecd37f1311928 |
| Linux/Linuxgeneric | 2.6.28 | Not reported |
Published upstream
Sep 25, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 25, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 25, 2026
In the Linux kernel, the following vulnerability has been resolved: ALSA: us122l: Prevent write upgrades for read mappings The hwdep mmap callback rejects read-buffer mappings that are initially writable, but leaves VM_MAYWRITE set on mappings created with PROT_READ. A process that can open the hwdep node O_RDWR can later use mprotect() to make the mapping writable. The read allocation begins with struct usb_stream. Its read_size member is used by the fault handler to decide which pages belong to the read buffer. The read VMA intentionally remains expandable because pcm_usb_stream uses mremap() after reading that size. Changing read_size first can therefore map and access pages beyond the allocation. The same member is also consumed by usb_stream_free(), where changing it can make free_pages_exact() release pages outside the allocation. Clear VM_MAYWRITE for read-buffer mappings after rejecting an initially writable VMA. This keeps the separate output-buffer mapping writable while preventing later permission upgrades.
Quoted source text, attributed separately from HOL analysis.