← All Advisories

CVE-2026-97931

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-97931

Key Details

CVECVE-2026-97931
CVSS Score / Version7.0 (High) / CVSS v3.1
Updated2026-09-25
CVSS VectorCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is local; attack complexity is high; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

ALSA: us122l: Prevent write upgrades for read mappings

The hwdep mmap callback rejects read-buffer mappings that are initially

writable, but leaves VM_MAYWRITE set on mappings created with PROT_READ.

A process that can open the hwdep node O_RDWR can later use mprotect() to

make the mapping writable.

The read allocation begins with struct usb_stream. Its read_size member is

used by the fault handler to decide which pages belong to the read buffer.

The read VMA intentionally remains expandable because pcm_usb_stream uses

mremap() after reading that size. Changing read_size first can therefore

map and access pages beyond the allocation. The same member is also

consumed by usb_stream_free(), where changing it can make

free_pages_exact() release pages outside the allocation.

Clear VM_MAYWRITE for read-buffer mappings after rejecting an initially

writable VMA. This keeps the separate output-buffer mapping writable while

preventing later permission upgrades. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-97931
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-97931