Junglewise Threat Intelligence

CVE-2026-23191: Linux kernel ALSA aloop race condition in PCM trigger

CVE-2026-23191 · Severity: high · CVSS 7.8 · Published 2026-02-14

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The ALSA (Advanced Linux Sound Architecture) aloop driver contains a race condition in its PCM (Pulse Code Modulation) trigger callback that can cause a use-after-free (UAF) crash when audio streams are rapidly opened, closed, and triggered simultaneously. An attacker with local access could exploit this to crash the kernel or potentially execute arbitrary code, disrupting audio services and system stability.

Technical details

The vulnerability is a use-after-free (UAF) race condition in the aloop driver's loopback_check_format() function. The PCM trigger callback checks the state of tied PCM substreams and may stop them, but these operations were performed outside the cable spinlock, creating a race window. When a program triggers PCM operations frequently while simultaneously opening/closing the tied stream, pointers can become invalid between the check and the stop operations. The fix wraps the critical section with cable->lock spinlock protection and adds NULL pointer checks before accessing stream state. The vulnerability requires local system access to trigger but can cause kernel panic (denial of service) via a fuzzer-like workload.

Affected products

  • Linux Linux kernel Multiple versions (patched in 6.14 and backported to stable series)

Timeline

  • 2026-02-14: disclosed: Published as CVE-2026-23191
  • 2026-02-03: patched: Upstream patch merged (commit 826af7fa62e347464b1b4e0ba2fe19a92438084f)
  • 2026-02-11: patched: Backported to stable kernels via commit 5727ccf9d19ca414cb76d9b647883822e2789c2e

References

Related threats