CVE-2026-97931
Błąd w jądrze Linux umożliwia eskalację uprawnień przez modyfikację mapowania pamięci.
In the Linux kernel, the following vulnerability has been resolved: ALSA: us122l: Prevent write upgrades for read mappings The hwdep mmap callback rejects read-buffer mappings that are initially writable, but leaves VM_MAYWRITE set on mappings created with PROT_READ. A process that can open the hwdep node O_RDWR can later use mprotect() to make the mapping writable. The read allocation begins with struct usb_stream. Its read_size member is used by the fault handler to decide which pages belong to the read buffer. The read VMA intentionally remains expandable because pcm_usb_stream uses mremap() after reading that size. Changing read_size first can therefore map and access pages beyond the allocation. The same member is also consumed by usb_stream_free(), where changing it can make free_pages_exact() release pages outside the allocation. Clear VM_MAYWRITE for read-buffer mappings after rejecting an initially writable VMA. This keeps the separate output-buffer mapping writable while preventing later permission upgrades.
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 7.0 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.1% |
| Opublikowano (NVD) | 2026-09-25 11:17:20 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-03 11:18:10 UTC |
- https://git.kernel.org/stable/c/0eb9dd4774af0ac4d1fd105ef2b0a1f6cec06f2f (416baaa9-dc9f-4396-8d5f-8c081fb06d67)
- https://git.kernel.org/stable/c/64a87950239867682cde128020e1a47088295e5c (416baaa9-dc9f-4396-8d5f-8c081fb06d67)
- https://git.kernel.org/stable/c/6a5f5a5a32c78e67701f1d0f26bc87af68895604 (416baaa9-dc9f-4396-8d5f-8c081fb06d67)
- https://git.kernel.org/stable/c/71c610aeb1770302ac9c9e0b9a4ecd37f1311928 (416baaa9-dc9f-4396-8d5f-8c081fb06d67)
- https://git.kernel.org/stable/c/938e8d6cee8d36f24669dfdcd3717e081eb32d64 (416baaa9-dc9f-4396-8d5f-8c081fb06d67)
- https://git.kernel.org/stable/c/becb89036a1320ef0a77da2d27935ac0704345c4 (416baaa9-dc9f-4396-8d5f-8c081fb06d67)
- https://git.kernel.org/stable/c/cbc1f954ce67d739d41d1f0757d29850353ebb6a (416baaa9-dc9f-4396-8d5f-8c081fb06d67)
- https://git.kernel.org/stable/c/d9c537b14f4982f17b103e3a2cfeee4bee6bc026 (416baaa9-dc9f-4396-8d5f-8c081fb06d67)