CVE-2026-23191: ALSA: aloop: Fix racy access at PCM trigger
Published Feb 14, 2026
·Updated
ALSA: aloop: Fix racy access at PCM trigger
Affected Software
15 affected components
linux/kernel
Linux Linux kernel>=2.6.37<6.12.70
Linux Linux kernel>=6.13<6.18.10
Linux Linux kernel=6.19-rc1
Linux Linux kernel=6.19-rc2
Linux Linux kernel=6.19-rc3
Linux Linux kernel=6.19-rc4
Linux Linux kernel=6.19-rc5
Linux Linux kernel=6.19-rc6
Linux Linux kernel=6.19-rc7
Linux Linux kernel=6.19-rc8
IBM Verify Identity Access<=11.0 - 11.0.2
IBM Security Verify Access<=10.0 - 10.0.9.1
IBM Verify Identity Access Container<=11.0 - 11.0.2
IBM Security Verify Access Container<=10.0 - 10.0.9.1
Event History
Feb 14, 2026
CVE Published
via MITRE·04:27 PM
Data Sourced
via MITRE·04:27 PM
DescriptionSeverity
Data Sourced
via Red Hat·05:04 PM
DescriptionSeverityAffected Software
Data Sourced
via NVD·05:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Mar 20, 2026
Data Sourced
via Microsoft·08:03 AM
DescriptionSeverityWeakness
Jul 8, 2026
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-23191?
CVE-2026-23191 has been classified as a medium severity vulnerability affecting the ALSA subsystem.
2
How do I fix CVE-2026-23191?
To resolve CVE-2026-23191, users should upgrade to the latest version of the Linux kernel where the vulnerability has been patched.
3
What impact does CVE-2026-23191 have on systems?
CVE-2026-23191 can lead to race conditions in the PCM trigger function, potentially causing instability in audio streaming.
4
Is CVE-2026-23191 present in older Linux kernel versions?
Yes, CVE-2026-23191 is present in older versions of the Linux kernel that utilize the ALSA aloop driver.
5
How can I determine if my system is affected by CVE-2026-23191?
To check if your system is affected by CVE-2026-23191, verify the version of your Linux kernel against the patched versions.