Junglewise Threat Intelligence

CVE-2025-39997: Linux Kernel ALSA usb-audio use-after-free in snd_usbmidi_free

CVE-2025-39997 · Severity: info · CVSS 4.6 · Published 2025-10-15

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's USB audio driver that could lead to a system crash or unpredictable behavior. The issue occurs when a USB MIDI device is disconnected, potentially allowing the system to access memory that has already been freed. This could be exploited by a local user to cause a denial of service or potentially gain unauthorized access to system information.

Technical details

A use-after-free (UAF) vulnerability exists in the snd_usbmidi_free function within the ALSA usb-audio driver (sound/usb/midi.c). The root cause is a race condition where the error timer and USB Request Blocks (URBs) are not properly synchronized or killed before heap memory is freed. Specifically, if an error timer or URB interrupt occurs after the endpoint is deleted but before the memory is fully cleared, the kernel attempts to access freed memory. This was a regression or incomplete fix for a previous UAF issue. The fix involves ensuring snd_usbmidi_disconnect is called and that timers/URBs are shut down before memory deallocation. Patch availability is confirmed across multiple stable kernel branches.

Affected products

  • Linux Linux Kernel ALSA usb-audio component

Timeline

  • 2025-09-28: patched: Initial fix committed to mainline kernel
  • 2025-10-15: disclosed: CVE-2025-39997 published

References

Related threats