CVE-2025-38078
Published: Jun 18, 2025
Modified: May 11, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: ALSA: pcm: Fix race of buffer access at PCM OSS layer The PCM OSS layer tries to clear the buffer with the silence data at initialization (or reconfiguration) of a stream with the explicit call of snd_pcm_format_set_silence() with runtime->dma_area. But this may lead to a UAF because the accessed runtime->dma_area might be freed concurrently, as it's performed outside the PCM ops. For avoiding it, move the code into the PCM core and perform it inside the buffer access lock, so that it won't be changed during the operation.
| Vendor | Product | Versions |
|---|---|---|
Linux | Linux | affected 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 - < c0e05a76fc727929524ef24a19c302e6dd40233faffected 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 - < 8170d8ec4efd0be352c14cb61f374e30fb0c2a25affected 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 - < 10217da9644ae75cea7330f902c35fc5ba78bbbfaffected 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 - < f3e14d706ec18faf19f5a6e75060e140fea05d4aaffected 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 - < 74d90875f3d43f3eff0e9861c4701418795d3455+3 more versions |
Linux | Linux | affected 2.6.12unaffected 0 - < 2.6.12unaffected 5.4.294 - <= 5.4.*unaffected 5.10.238 - <= 5.10.*unaffected 5.15.185 - <= 5.15.*+5 more versions |
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now