Description
In the Linux kernel, the following vulnerability has been resolved:

ALSA: seq: Don't leak the extension cell pointer in the bounce payload

The bounce_error_event() embeds the failed event in the bounce payload
by pointing data.ext.ptr at it. When that event is a queued
variable-length event, its own data.ext.ptr holds the address of its
first extension cell, put there by snd_seq_event_dup(). The payload
goes out verbatim through snd_seq_expand_var_event(), so the address
reaches userspace.

That is the same address commit 705dd6dcbc0e ("ALSA: seq: Clear
variable event pointer on read") removed from the event header. The
read path still clears it there, just above the call that expands the
payload.

Embed a sanitised copy instead, treated exactly as snd_seq_read()
treats the header. A stack copy is enough because delivery is
synchronous and snd_seq_event_dup() copies before returning.

An unprivileged client reaches this by setting SNDRV_SEQ_FILTER_BOUNCE,
queueing a variable-length event to a port that does not exist and
reading the bounce back. Eight bytes on 64-bit, from its own pool.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure: Kernel address leakage to userspace
Action: Update Kernel
AI Analysis

Impact

This vulnerability resides in the ALSA sequencer of the Linux kernel. During error handling, the bounce_error_event() routine embeds the failed event directly into the bounce payload by pointing data.ext.ptr at it. When that event is a queued variable‑length event, its own data.ext.ptr holds the address of its first extension cell. The payload is then transmitted unmodified, exposing that internal address to userspace. The effect is that an attacker can obtain a kernel‑space pointer value, which may be used for subsequent information‑disclosure attacks or lead to privilege escalation. The weakness is a classic information‑leak flaw (CWE‑200).

Affected Systems

The flaw affects all Linux kernel implementations that contain the ALSA sequencer before the fix that removed the pointer from the event header. Packages that ship the kernel before the commit referenced in the advisory are vulnerable. The advisory lists Linux as the affected vendor; specific product versions are not enumerated in the data.

Risk and Exploitability

The EPSS score is below 1%, and it is not listed in CISA’s KEV catalog, suggesting low exploitation probability. However, the attack can be carried out by any unprivileged local user who can set the SNDRV_SEQ_FILTER_BOUNCE flag, queue a variable‑length event to a nonexistent ALSA port, and read the bounce response. Although the vulnerability is local, an attacker may leverage the disclosed address to carry out additional kernel‑based exploits. The CVSS score is not provided; nevertheless the combination of local access and kernel memory disclosure warrants attention.

Generated by OpenCVE AI on September 20, 2026 at 01:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that includes the fix from commit 42c3f856…
  • If an update is not possible, disable the bouncing feature by preventing the use of SNDRV_SEQ_FILTER_BOUNCE or removing variable‑length event support from the ALSA sequencer
  • Restrict ALSA sequencer access to privileged users only, for example by adjusting /etc/security/access or applying Linux capabilities limits

Generated by OpenCVE AI on September 20, 2026 at 01:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sun, 20 Sep 2026 01:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: ALSA: seq: Don't leak the extension cell pointer in the bounce payload The bounce_error_event() embeds the failed event in the bounce payload by pointing data.ext.ptr at it. When that event is a queued variable-length event, its own data.ext.ptr holds the address of its first extension cell, put there by snd_seq_event_dup(). The payload goes out verbatim through snd_seq_expand_var_event(), so the address reaches userspace. That is the same address commit 705dd6dcbc0e ("ALSA: seq: Clear variable event pointer on read") removed from the event header. The read path still clears it there, just above the call that expands the payload. Embed a sanitised copy instead, treated exactly as snd_seq_read() treats the header. A stack copy is enough because delivery is synchronous and snd_seq_event_dup() copies before returning. An unprivileged client reaches this by setting SNDRV_SEQ_FILTER_BOUNCE, queueing a variable-length event to a port that does not exist and reading the bounce back. Eight bytes on 64-bit, from its own pool.
Title ALSA: seq: Don't leak the extension cell pointer in the bounce payload
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:07:31.423Z

Reserved: 2026-09-11T19:38:34.793Z

Link: CVE-2026-90220

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:17.440

Modified: 2026-09-17T17:17:17.440

Link: CVE-2026-90220

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T01:30:16Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor