CVE-2026-53192: ALSA: timer: Fix UAF at snd_timer_user_params()
In the Linux kernel, the following vulnerability has been resolved:
ALSA: timer: Fix UAF at sndtimeruserparams()
At releasing a timer object, e.g. when a userspace timer (CONFIGSNDUTIMER) gets closed and sndtimerfree() is called, it tries to detach the timer instances and release the resources. However, it's still possible that other in-flight tasks are holding the timer instance where the to-be-deleted timer object is associated, and this may lead to racy accesses.
Fortunately, most of ioctls dealing with the timer instance list already have the protection with registermutex, and this also avoids such races. But, SNDRVTIMERIOCTLPARAMS isn't protected, hence the concurrent ioctl may lead to use-after-free.
This patch just adds the guard with registermutex to protect sndtimeruserparams() for covering the code path as a quick workaround. It's no hot-path but rather a rarely issued ioctl, so the performance penalty doesn't matter.
Affected Software
Event History
Frequently Asked Questions
Who is realistically exposed to this issue?
Systems using the affected Linux kernel ALSA timer functionality are exposed, including the listed Microsoft azl3 kernel 6.6.143.1-1. Exploitation requires local access with low privileges, as reflected by the AV:L and PR:L vector.
What race condition is required for exploitation?
An attacker needs a concurrent SNDRV_TIMER_IOCTL_PARAMS operation while a timer object is being released and its associated timer instances are being detached. The vulnerable path can occur when a userspace timer is closed with CONFIG_SND_UTIMER enabled.
Is this triggered by normal high-frequency timer activity?
The affected operation is SNDRV_TIMER_IOCTL_PARAMS, which the fix describes as a rarely issued ioctl rather than a hot-path operation. The race specifically involves this ioctl lacking the register_mutex protection already used by most timer-instance list ioctls.
What does the fix change?
The fix protects snd_timer_user_params() with register_mutex. This serializes the parameters ioctl against timer-object release and prevents racy accesses to a timer instance associated with a deleted timer object.