{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-64029","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-07-19T07:54:57.028Z","datePublished":"2026-07-19T15:39:20.368Z","dateUpdated":"2026-08-05T12:38:23.130Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-05T12:38:23.130Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: seq: Serialize UMP output teardown with event_input\n\nseq_ump_process_event() borrows client->out_rfile.output without\nsynchronizing with the first-open and last-close transition in\nseq_ump_client_open() and seq_ump_client_close().\n\nThe last output unuse can therefore drop opened[STR_OUT] to zero and\nrelease the rawmidi file while an in-flight event_input callback is still\ninside snd_rawmidi_kernel_write(). That leaves the rawmidi substream\nruntime exposed to teardown before the write path has taken its own\nbuffer reference.\n\nAdd a per-client rwlock for the event_input-visible output file. Publish\na newly opened output file under the write side, and hold the read side\nfrom the output lookup through snd_rawmidi_kernel_write(). The last\noutput close copies and clears the visible output file under the write\nside, then drops the lock and releases the saved rawmidi file. Use\nIRQ-safe rwlock guards because event_input can also be reached from\natomic sequencer delivery.\n\nThe buggy scenario involves two paths, with each column showing the\norder within that path:\n\npath A label: event_input path         path B label: last unuse path\n1. seq_ump_process_event() reads       1. seq_ump_client_close()\n   client->out_rfile.output.              drops opened[STR_OUT] to zero.\n2. snd_rawmidi_kernel_write1()         2. snd_rawmidi_kernel_release()\n   has not yet pinned runtime.            closes the output file.\n3. The writer continues using          3. close_substream() frees\n   the borrowed substream.                substream->runtime.\n\nThis keeps the output substream and runtime alive for the full\nevent_input write while keeping rawmidi release outside the rwlock.\n\nKASAN reproduced this as a slab-use-after-free in\nsnd_rawmidi_kernel_write1(), with allocation through\nseq_ump_use()/snd_seq_port_connect() and free through\nseq_ump_unuse()/snd_seq_port_disconnect().\n\n\nValidation reproduced this kernel report:\nKASAN slab-use-after-free in snd_rawmidi_kernel_write1+0x9d/0x400\nRIP: 0033:0x7f5528af837f\nRead of size 8\nCall trace:\n  dump_stack_lvl+0x73/0xb0 (?:?)\n  print_report+0xd1/0x650 (?:?)\n  srso_alias_return_thunk+0x5/0xfbef5 (?:?)\n  __virt_addr_valid+0x1a7/0x340 (?:?)\n  kasan_complete_mode_report_info+0x64/0x200 (?:?)\n  kasan_report+0xf7/0x130 (?:?)\n  snd_rawmidi_kernel_write1+0x9d/0x400 (?:?)\n  __asan_load8+0x82/0xb0 (?:?)\n  update_stack_state+0x1ef/0x2d0 (?:?)\n  snd_rawmidi_kernel_write+0x1a/0x20 (?:?)\n  seq_ump_process_event+0xd4/0x120 (sound/core/seq/seq_ump_client.c:82)\n  __snd_seq_deliver_single_event+0x8a/0xe0 (?:?)\n  snd_seq_deliver_from_ump+0x2b2/0xd60 (?:?)\n  lock_acquire+0x14e/0x2e0 (?:?)\n  find_held_lock+0x31/0x90 (?:?)\n  snd_seq_port_use_ptr+0xa6/0xe0 (?:?)\n  __kasan_check_write+0x18/0x20 (?:?)\n  do_raw_read_unlock+0x32/0xa0 (?:?)\n  _raw_read_unlock+0x26/0x50 (?:?)\n  snd_seq_deliver_single_event+0x45c/0x4b0 (?:?)\n  snd_seq_deliver_event+0x10d/0x1b0 (?:?)\n  snd_seq_client_enqueue_event+0x192/0x240 (?:?)\n  snd_seq_write+0x2cd/0x450 (?:?)\n  apparmor_file_permission+0x20/0x30 (?:?)\n  security_file_permission+0x51/0x60 (?:?)\n  vfs_write+0x1ce/0x850 (?:?)\n  __fget_files+0x12b/0x220 (?:?)\n  lock_release+0xc8/0x2a0 (?:?)\n  __rcu_read_unlock+0x74/0x2d0 (?:?)\n  __fget_files+0x135/0x220 (?:?)\n  ksys_write+0x15a/0x180 (?:?)\n  rcu_is_watching+0x24/0x60 (?:?)\n  __x64_sys_write+0x46/0x60 (?:?)\n  x64_sys_call+0x7d/0x20d0 (?:?)\n  do_syscall_64+0xc1/0x360 (arch/x86/entry/syscall_64.c:87)\n  entry_SYSCALL_64_after_hwframe+0x77/0x7f (?:?)"}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - Exploitation requires local access via the ALSA sequencer device node (/dev/snd/seq) using write(2) and port-subscription ioctls; there is no network, Bluetooth, or physical-device attack surface on the vulnerable code path.\nAC:L - The race is between concurrent UMP event delivery and the last output-port unsubscribe/close path, and a local attacker can control both sides with parallel threads (flood write() while repeatedly subscribing/unsubscribing to the UMP port).\nPR:L - Any local unprivileged user who can open /dev/snd/seq (typically membership in the audio group on desktop/workstation systems where UMP MIDI hardware is present) can create sequencer clients, subscribe to UMP kernel ports, and trigger the bug without real root or init-namespace capabilities.\nUI:N - Exploitation is fully attacker-driven through sequencer writes and subscription management; no victim interaction such as opening files, mounting filesystems, or plugging in devices is required beyond the UMP endpoint already being present on the system.\nS:U - Impact is confined to kernel memory corruption and potential local privilege escalation within the same kernel security boundary; this is not a VM escape, sandbox escape, or cross-authority boundary bypass.\nC:H - KASAN confirmed a slab use-after-free on freed substream runtime metadata in snd_rawmidi_kernel_write1(); UAF on kernel heap objects enables controlled reallocation and arbitrary kernel memory disclosure primitives.\nI:H - The UAF occurs inside snd_rawmidi_kernel_write1(), which performs memcpy() into runtime->buffer using attacker-supplied UMP event payload, providing a plausible path to arbitrary kernel memory corruption and code execution beyond a simple crash.\nA:H - The confirmed KASAN slab-use-after-free in kernel write path causes kernel oops/panic; even without full exploitation, the bug reliably threatens system availability through kernel crash."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["sound/core/seq/seq_ump_client.c"],"versions":[{"version":"81fd444aa371261cd33f31d4ffd80faeeeab0cc9","lessThan":"8ba1c4ddbb1c67d34bb440aecb9f5690ed3f64cb","status":"affected","versionType":"git"},{"version":"81fd444aa371261cd33f31d4ffd80faeeeab0cc9","lessThan":"0cb1ad795570167558530d6194297ac2396a1991","status":"affected","versionType":"git"},{"version":"81fd444aa371261cd33f31d4ffd80faeeeab0cc9","lessThan":"3aab4a58d23fb22dac5b558bbe5df1a8dad00b4b","status":"affected","versionType":"git"},{"version":"81fd444aa371261cd33f31d4ffd80faeeeab0cc9","lessThan":"ef46b616a4c219185bbf10ebcbacb571583fd0e4","status":"affected","versionType":"git"},{"version":"81fd444aa371261cd33f31d4ffd80faeeeab0cc9","lessThan":"60a1969fae6209644698fca91c185d153674f631","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["sound/core/seq/seq_ump_client.c"],"versions":[{"version":"6.5","status":"affected"},{"version":"0","lessThan":"6.5","status":"unaffected","versionType":"semver"},{"version":"6.6.142","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.92","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.34","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.0.11","lessThanOrEqual":"7.0.*","status":"unaffected","versionType":"semver"},{"version":"7.1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.5","versionEndExcluding":"6.6.142"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.5","versionEndExcluding":"6.12.92"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.5","versionEndExcluding":"6.18.34"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.5","versionEndExcluding":"7.0.11"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.5","versionEndExcluding":"7.1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/8ba1c4ddbb1c67d34bb440aecb9f5690ed3f64cb"},{"url":"https://git.kernel.org/stable/c/0cb1ad795570167558530d6194297ac2396a1991"},{"url":"https://git.kernel.org/stable/c/3aab4a58d23fb22dac5b558bbe5df1a8dad00b4b"},{"url":"https://git.kernel.org/stable/c/ef46b616a4c219185bbf10ebcbacb571583fd0e4"},{"url":"https://git.kernel.org/stable/c/60a1969fae6209644698fca91c185d153674f631"}],"title":"ALSA: seq: Serialize UMP output teardown with event_input","x_generator":{"engine":"bippy-1.2.0"}}}}