Junglewise Threat Intelligence

CVE-2026-74278: Linux kernel ALSA seq kernel heap address leak in bounce_error_event()

CVE-2026-74278 · Severity: info · Published 2026-08-15

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's ALSA sequencer module inadvertently exposes kernel memory addresses to unprivileged user applications when handling bounce error events. An attacker with local access could exploit this information disclosure to bypass kernel address space layout randomization (KASLR), compromising the effectiveness of memory protection mechanisms used to prevent more severe exploits.

Technical details

A kernel heap address leak vulnerability exists in the ALSA seq driver's bounce_error_event() function. The bug occurs because bounce error events unconditionally use SNDRV_SEQ_EVENT_KERNEL_ERROR with a raw kernel struct snd_seq_event pointer in the data.quote.event field, regardless of client type. When delivered to a USER_CLIENT via snd_seq_read(), this raw kernel pointer is copied to userspace via copy_to_user() in the fixed-length event branch, bypassing existing sanitization that occurs only in the variable-length path. The fix differentiates behavior by client type: USER_CLIENT now receives SNDRV_SEQ_EVENT_BOUNCE with variable-length data pointing to the original event (whose contents are copied safely without exposing pointers), while KERNEL_CLIENT retains the original behavior. The vulnerability requires local access and affects kernels prior to the patch.

Affected products

  • Linux Linux kernel prior to fix

Timeline

  • 2026-08-15: disclosed
  • 2026-08-15: patched

Related threats