Review reviewHigh

CVE-2026-46090

Linux Linux, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10.0 Extended Update Support

In the Linux kernel, the following vulnerability has been resolved: ALSA: aloop: Fix peer runtime UAF during format-change stop loopback_check_format() may stop the capture side when playback starts with parameters that no longer match a running capture stream. Commit 826af7fa62e3 ("ALSA: aloop: Fix racy access at PCM trigger") moved the peer lookup under cable->lock, but the actual snd_pcm_stop() still runs after dropping that lock. A concurrent close can clear the capture entry from cable->streams[] and detach or free its runtime while the playback trigger path still holds a stale peer su...

CVSS
7.8
EPSS
0.10%
1.16% percentile
CISA KEV
Not listed
Published
2026.05.27
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability0.10%
Technical severityCVSS 7.8

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: ALSA: aloop: Fix peer runtime UAF during format-change stop loopback_check_format() may stop the capture side when playback starts with parameters that no longer match a running capture stream. Commit 826af7fa62e3 ("ALSA: aloop: Fix racy access at PCM trigger") moved the peer lookup under cable->lock, but the actual snd_pcm_stop() still runs after dropping that lock. A concurrent close can clear the capture entry from cable->streams[] and detach or free its runtime while the playback trigger path still holds a stale peer su...

Affected product and versions

Product
Linux Linux, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10.0 Extended Update Support
Affected versions
>= 597603d615d2b19a9e451d8cfac24372856a522d < 83bd62fa9620ac98d5d694bde14c50f98c8e7189, >= 597603d615d2b19a9e451d8cfac24372856a522d < 345c24b2bcf0923dfae1ab41497351c68214ff76, >= 597603d615d2b19a9e451d8cfac24372856a522d < 03f52a9c170431e8f10e156b9dc0dae80b3e9198, >= 597603d615d2b19a9e451d8cfac24372856a522d < bdd9503c3d222d2735b56c7a8b4422ccf3de6e5c, >= 597603d615d2b19a9e451d8cfac24372856a522d < 5d45e34bf001344e2966dabca1897561bbc9e913, >= 597603d615d2b19a9e451d8cfac24372856a522d < e5c33cdc6f402eab8abd36ecf436b22c9d3a8aff, >= 2.6.37, >= 2.6.37 < 5.10.259, >= 5.11 < 5.15.210, >= 5.16 < 6.12.88, >= 6.13 < 6.18.27, >= 6.19 < 7.0.4, 7.1
Fixed versions
5.10.259, 5.15.210, 6.12.88, 6.18.27, 7.0.4

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux Linux, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10.0 Extended Update Support and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-364, CWE-416
CVE-2026-46090 — Linux Linux, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10.0 Extended Update Support | SECUFOCUS NOW