Description
In the Linux kernel, the following vulnerability has been resolved:

ALSA: mtpav: shut down output timer before card teardown

snd_mtpav_output_timer() rearms chip->timer while holding
chip->spinlock and accesses the card-private mtpav state.

snd_mtpav_free() currently takes the same lock and calls
timer_delete() when the timer is active. This only removes a
pending timer; it does not wait for a callback that is already
running and does not prevent the callback from rearming the timer.

A callback running on another CPU can therefore continue after
snd_mtpav_free() releases the lock and access the card-private
state while the card is being torn down. It can also rearm the
timer after timer_delete() has returned.

Call timer_shutdown_sync() without holding chip->spinlock. This
waits for any running callback to finish and prevents further
rearming before the card-private mtpav state is released.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Use-After-Free
Action: Patch
AI Analysis

Impact

The ALSA mtpav driver in the Linux kernel schedules an output timer that can be re‑armed by a callback executing on a different CPU. During card teardown the driver releases the spinlock and deletes the timer, but it does not wait for any callbacks that are currently running. As a result, the callback may continue after the driver has been freed, accessing freed memory and potentially re‑arming the timer. This race condition can lead to a use‑after‑free vulnerability that may allow an attacker to execute arbitrary code in kernel space.

Affected Systems

Linux kernel, specifically the ALSA mtpav audio driver. No specific version information is listed in the advisory.

Risk and Exploitability

The CVSS score is not disclosed in the provided data, but the EPSS identifier of less than 1% indicates a very low probability that this race condition would be exploited in practice. The vulnerability is not listed in the CISA KEV catalog, further suggesting it is not currently being actively exploited. An attacker would need local access and a precise timing window where a callback is still running while the audio card is being torn down, a scenario that is relatively narrow and unlikely.

Generated by OpenCVE AI on September 18, 2026 at 22:34 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that includes the fix which calls timer_shutdown_sync() without holding the spinlock.
  • If an update is not available, unload or disable the mtpav module or the ALSA audio subsystem to eliminate the use of the vulnerable timer.
  • For environments that must keep the driver loaded, avoid performing card teardown operations while the driver is in use, and add system-level checks to ensure no callbacks are running before unloading the module.

Generated by OpenCVE AI on September 18, 2026 at 22:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: ALSA: mtpav: shut down output timer before card teardown snd_mtpav_output_timer() rearms chip->timer while holding chip->spinlock and accesses the card-private mtpav state. snd_mtpav_free() currently takes the same lock and calls timer_delete() when the timer is active. This only removes a pending timer; it does not wait for a callback that is already running and does not prevent the callback from rearming the timer. A callback running on another CPU can therefore continue after snd_mtpav_free() releases the lock and access the card-private state while the card is being torn down. It can also rearm the timer after timer_delete() has returned. Call timer_shutdown_sync() without holding chip->spinlock. This waits for any running callback to finish and prevents further rearming before the card-private mtpav state is released.
Title ALSA: mtpav: shut down output timer before card teardown
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:06:22.065Z

Reserved: 2026-09-11T19:38:34.787Z

Link: CVE-2026-90116

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:03.747

Modified: 2026-09-17T17:17:03.747

Link: CVE-2026-90116

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T22:45:15Z

Weaknesses