Junglewise Threat Intelligence

CVE-2026-43437: Linux Kernel ALSA use-after-free in snd_pcm_drain

CVE-2026-43437 · Severity: high · CVSS 7.8 · Published 2026-05-08

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability exists in the Linux kernel's sound subsystem (ALSA) that could allow a local user to crash the system or potentially execute unauthorized code. The issue occurs when the system handles audio streams that are being closed and drained simultaneously. This could lead to a loss of system availability or unauthorized access to sensitive data.

Technical details

A use-after-free vulnerability exists in sound/core/pcm_native.c within the snd_pcm_drain() function. The root cause is a race condition where a linked stream's runtime object is accessed after its lock is released, but before it is properly protected by a reference count. A concurrent close() operation on the linked stream can trigger kfree(runtime), leading to a stale pointer dereference when the drain loop attempts to access fields like no_period_wakeup, rate, and buffer_size. Local attackers can exploit this by timing stream operations to trigger the race. Patches have been released for multiple stable kernel branches to cache the required fields while the lock is still held.

Affected products

  • Linux Linux Kernel versions from 3.0 up to 5.10.253; 5.11 up to 6.1.167; 6.2 up to 6.6.130; 6.7 up to 6.12.78; 6.13 up to 6.18.19; 6.19 up to 6.19.9

Timeline

  • 2026-03-05: other: Patch authored
  • 2026-05-08: disclosed: Initial publication date
  • 2026-05-08: advisory

References

Related threats