Executive brief
The Linux kernel's ALSA (Advanced Linux Sound Architecture) sequencer component leaks internal kernel memory addresses to unprivileged user-space applications. A local user can craft a specially formed audio sequencer event and read back kernel pointer values, which can be used to defeat kernel address space layout randomization (ASLR) protections—a common stepping stone toward privilege escalation exploits.
Technical details
The vulnerability is an information disclosure flaw in the snd_seq_read() function in sound/core/seq/seq_clientmgr.c. When reading variable-length sequencer events, the kernel copies an event header to user-space but failed to clear the data.ext.ptr field, which contains a kernel-space pointer to an internal extension cell. While the code strips SNDRV_SEQ_EXT_* mask bits from data.ext.len, it leaves the pointer untouched. An unprivileged local user with access to the sequencer API can write a direct variable event to themselves and then read back the uncleared pointer, leaking kernel memory layout information. The fix is a single-line change to set tmpev.data.ext.ptr to NULL before the copy_to_user() call. No network vector, user interaction, or elevated privileges are required beyond local sequencer access.
Affected products
- Linux Linux kernel 2.6.12 and later (all stable series through 7.2)
Timeline
- 2026-08-15: disclosed
- 2026-07-24: patched