Answer in brief
CVE-2026-98314 records a Unknown severity vulnerability in ALSA: pcm: set timer->private_data before registering the PCM timer. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <27f167e117eca310661fbcbacb352ea08face067 || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <555d168bd98daa46daccc68c908201388c834293 || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <8c869d5cf5affb20994bdbb60e7d46d65c91b55f || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <686c7a6af1eea8d2a919303e4c6bbec3de79dbdc || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <e1eee8f16628f8b6bcae0a366fd6a2dd65e71edd || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <d63f5a9f8121fb43c798056d7dd34c58f47185d7 || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <0b349249d572633d7c8cdeb917623d1676a2b7c3 || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <1e713f9bb2ac583521f06b0eb4e22440b1e3d078 | 27f167e117eca310661fbcbacb352ea08face067, 555d168bd98daa46daccc68c908201388c834293, 8c869d5cf5affb20994bdbb60e7d46d65c91b55f, 686c7a6af1eea8d2a919303e4c6bbec3de79dbdc, e1eee8f16628f8b6bcae0a366fd6a2dd65e71edd, d63f5a9f8121fb43c798056d7dd34c58f47185d7, 0b349249d572633d7c8cdeb917623d1676a2b7c3, 1e713f9bb2ac583521f06b0eb4e22440b1e3d078 |
| Linux/Linuxgeneric | 2.6.12 | Not reported |
Published upstream
Oct 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Oct 6, 2026
In the Linux kernel, the following vulnerability has been resolved: ALSA: pcm: set timer->private_data before registering the PCM timer snd_pcm_timer_init() calls snd_device_register() to link the new struct snd_timer into the global timer list while it still carries hw.c_resolution = snd_pcm_timer_resolution (and hw.start/hw.stop), and only afterwards sets timer->private_data = substream. Once the timer is on the list under register_mutex, a concurrent reader can already reach it through the same mutex and invoke these callbacks. /proc/asound/timers does this via c_resolution(), and snd_timer_open()+snd_timer_start() reach start()/stop() the same way. All three dereference timer->private_data, which for this brief window is NULL, giving a NULL-pointer dereference: substream = timer->private_data; return substream->runtime ? ... // substream is NULL Move the private_data/private_free assignment before snd_device_register() so the timer is never visible on the list without its private_data set. On the snd_device_register() failure path, private_free() (snd_pcm_timer_free()) can now run, but it only does substream->timer = NULL, which is already NULL at that point since substream->timer is set to the new timer just once, after a successful registration -- so the failure path stays safe.
Quoted source text, attributed separately from HOL analysis.