{"id":"AZL-106380","summary":"CVE-2026-98314 affecting package kernel 6.6.157.1-1","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: pcm: set timer-\u003eprivate_data before registering the PCM timer\n\nsnd_pcm_timer_init() calls snd_device_register() to link the new\nstruct snd_timer into the global timer list while it still carries\nhw.c_resolution = snd_pcm_timer_resolution (and hw.start/hw.stop),\nand only afterwards sets timer-\u003eprivate_data = substream.\n\nOnce the timer is on the list under register_mutex, a concurrent\nreader can already reach it through the same mutex and invoke these\ncallbacks. /proc/asound/timers does this via c_resolution(), and\nsnd_timer_open()+snd_timer_start() reach start()/stop() the same way.\nAll three dereference timer-\u003eprivate_data, which for this brief\nwindow is NULL, giving a NULL-pointer dereference:\n\n  substream = timer-\u003eprivate_data;\n  return substream-\u003eruntime ? ...   // substream is NULL\n\nMove the private_data/private_free assignment before\nsnd_device_register() so the timer is never visible on the list\nwithout its private_data set. On the snd_device_register() failure\npath, private_free() (snd_pcm_timer_free()) can now run, but it only\ndoes substream-\u003etimer = NULL, which is already NULL at that point\nsince substream-\u003etimer is set to the new timer just once, after a\nsuccessful registration -- so the failure path stays safe.","modified":"2026-10-08T05:35:32Z","published":"2026-10-06T09:18:23Z","upstream":["CVE-2026-98314"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-98314"}],"affected":[{"package":{"name":"kernel","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/kernel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"6.6.157.1-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-106380.json"}}],"schema_version":"1.9.0"}