CVE-2023-54072
published 2025-12-24CVE-2023-54072: In the Linux kernel, the following vulnerability has been resolved: ALSA: pcm: Fix potential data race at PCM memory allocation helpers The PCM memory…
PriorityP423medium6.3
EPSS
0.18%
7.7th percentile
In the Linux kernel, the following vulnerability has been resolved:
ALSA: pcm: Fix potential data race at PCM memory allocation helpers
The PCM memory allocation helpers have a sanity check against too many
buffer allocations. However, the check is performed without a proper
lock and the allocation isn't serialized; this allows user to allocate
more memories than predefined max size.
Practically seen, this isn't really a big problem, as it's more or
less some "soft limit" as a sanity check, and it's not possible to
allocate unlimitedly. But it's still better to address this for more
consistent behavior.
The patch covers the size check in do_alloc_pages() with the
card->memory_mutex, and increases the allocated size there for
preventing the further overflow. When the actual allocation fails,
the size is decreased accordingly.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.52-1 (bookworm) | linux 6.1.52-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 95b30a4312545f2dde9db12bf6a425f35d5a0d77 < 7e1d1456c8db9949459c5a24e8845cfe92430b0f | 7e1d1456c8db9949459c5a24e8845cfe92430b0f |
| linux | linux | >= d4cfb30fce03093ad944e0b44bd8f40bdad5330e < 7e11c58b2620a22c67a5ae28d64ce383890ee9f4 | 7e11c58b2620a22c67a5ae28d64ce383890ee9f4 |
| linux | linux | >= d4cfb30fce03093ad944e0b44bd8f40bdad5330e < a0ab49e7a758b488b2090171a75d50735c0876f6 | a0ab49e7a758b488b2090171a75d50735c0876f6 |
| linux | linux | >= d4cfb30fce03093ad944e0b44bd8f40bdad5330e < 3eb4e47a94e3f76521d7d344696db61e6a9619c7 | 3eb4e47a94e3f76521d7d344696db61e6a9619c7 |
| linux | linux | >= d4cfb30fce03093ad944e0b44bd8f40bdad5330e < 773ccad902f67583a58b5650a2f8d8daf2e76fac | 773ccad902f67583a58b5650a2f8d8daf2e76fac |
| linux | linux | >= d4cfb30fce03093ad944e0b44bd8f40bdad5330e < bd55842ed998a622ba6611fe59b3358c9f76773d | bd55842ed998a622ba6611fe59b3358c9f76773d |
| linux | linux_kernel | >= 0 < 5.10.197-1 | 5.10.197-1 |
| linux | linux_kernel | >= 0 < 6.1.52-1 | 6.1.52-1 |
| linux | linux_kernel | >= 0 < 6.4.4-1 | 6.4.4-1 |
| linux | linux_kernel | >= 0 < 6.4.4-1 | 6.4.4-1 |
| linux | linux_kernel | >= 5.11.0 < 5.15.129 | 5.15.129 |
| linux | linux_kernel | >= 5.16.0 < 6.1.39 | 6.1.39 |
| linux | linux_kernel | >= 5.6.0 < 5.10.193 | 5.10.193 |
| linux | linux_kernel | >= 6.2.0 < 6.4.4 | 6.4.4 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-xx23-73hr-9p64: In the Linux kernel, the following vulnerability has been resolved:
ALSA: pcm: Fix potential data race at PCM memory allocation helpers
The PCM memo
ghsa_unreviewed·2025-12-24
CVE-2023-54072 GHSA-xx23-73hr-9p64: In the Linux kernel, the following vulnerability has been resolved:
ALSA: pcm: Fix potential data race at PCM memory allocation helpers
The PCM memo
In the Linux kernel, the following vulnerability has been resolved:
ALSA: pcm: Fix potential data race at PCM memory allocation helpers
The PCM memory allocation helpers have a sanity check against too many
buffer allocations. However, the check is performed without a proper
lock and the allocation isn't serialized; this allows user to allocate
more memories than predefined max size.
Practically seen, this isn't really a big problem, as it's more or
less some "soft limit" as a sanity check, and it's not possible to
allocate unlimitedly. But it's still better to address this for more
consistent behavior.
The patch covers the size check in do_alloc_pages() with the
card->memory_mutex, and increases the allocated size there for
preventing the further overflow. When the actual allocation f
OSV
CVE-2023-54072: In the Linux kernel, the following vulnerability has been resolved: ALSA: pcm: Fix potential data race at PCM memory allocation helpers The PCM memory
osv·2025-12-24
CVE-2023-54072 CVE-2023-54072: In the Linux kernel, the following vulnerability has been resolved: ALSA: pcm: Fix potential data race at PCM memory allocation helpers The PCM memory
In the Linux kernel, the following vulnerability has been resolved: ALSA: pcm: Fix potential data race at PCM memory allocation helpers The PCM memory allocation helpers have a sanity check against too many buffer allocations. However, the check is performed without a proper lock and the allocation isn't serialized; this allows user to allocate more memories than predefined max size. Practically seen, this isn't really a big problem, as it's more or less some "soft limit" as a sanity check, and it's not possible to allocate unlimitedly. But it's still better to address this for more consistent behavior. The patch covers the size check in do_alloc_pages() with the card->memory_mutex, and increases the allocated size there for preventing the further overflow. When the actual allocation fails
OSV
ALSA: pcm: Fix potential data race at PCM memory allocation helpers
osv·2025-12-24
CVE-2023-54072 ALSA: pcm: Fix potential data race at PCM memory allocation helpers
ALSA: pcm: Fix potential data race at PCM memory allocation helpers
In the Linux kernel, the following vulnerability has been resolved:
ALSA: pcm: Fix potential data race at PCM memory allocation helpers
The PCM memory allocation helpers have a sanity check against too many
buffer allocations. However, the check is performed without a proper
lock and the allocation isn't serialized; this allows user to allocate
more memories than predefined max size.
Practically seen, this isn't really a big problem, as it's more or
less some "soft limit" as a sanity check, and it's not possible to
allocate unlimitedly. But it's still better to address this for more
consistent behavior.
The patch covers the size check in do_alloc_pages() with the
card->memory_mutex, and increases the allocated size th
Red Hat
kernel: Linux kernel: Denial of service or memory corruption due to a data race in ALSA PCM memory allocation
vendor_redhat·2025-12-24·CVSS 6.3
CVE-2023-54072 [MEDIUM] CWE-367 kernel: Linux kernel: Denial of service or memory corruption due to a data race in ALSA PCM memory allocation
kernel: Linux kernel: Denial of service or memory corruption due to a data race in ALSA PCM memory allocation
In the Linux kernel, the following vulnerability has been resolved:
ALSA: pcm: Fix potential data race at PCM memory allocation helpers
The PCM memory allocation helpers have a sanity check against too many
buffer allocations. However, the check is performed without a proper
lock and the allocation isn't serialized; this allows user to allocate
more memories than predefined max size.
Practically seen, this isn't really a big problem, as it's more or
less some "soft limit" as a sanity check, and it's not possible to
allocate unlimitedly. But it's still better to address this for more
consistent behavior.
The patch covers the size check in do_alloc_pages() with the
card->memory_mute
Debian
CVE-2023-54072: linux - In the Linux kernel, the following vulnerability has been resolved: ALSA: pcm: ...
vendor_debian·2023
CVE-2023-54072 CVE-2023-54072: linux - In the Linux kernel, the following vulnerability has been resolved: ALSA: pcm: ...
In the Linux kernel, the following vulnerability has been resolved: ALSA: pcm: Fix potential data race at PCM memory allocation helpers The PCM memory allocation helpers have a sanity check against too many buffer allocations. However, the check is performed without a proper lock and the allocation isn't serialized; this allows user to allocate more memories than predefined max size. Practically seen, this isn't really a big problem, as it's more or less some "soft limit" as a sanity check, and it's not possible to allocate unlimitedly. But it's still better to address this for more consistent behavior. The patch covers the size check in do_alloc_pages() with the card->memory_mutex, and increases the allocated size there for preventing the further overflow. When the actual allocation fails
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2023-54072 kernel: Linux kernel: Denial of service or memory corruption due to a data race in ALSA PCM memory allocation
bugzilla·2025-12-24
CVE-2023-54072 [MEDIUM] CVE-2023-54072 kernel: Linux kernel: Denial of service or memory corruption due to a data race in ALSA PCM memory allocation
CVE-2023-54072 kernel: Linux kernel: Denial of service or memory corruption due to a data race in ALSA PCM memory allocation
In the Linux kernel, the following vulnerability has been resolved:
ALSA: pcm: Fix potential data race at PCM memory allocation helpers
The PCM memory allocation helpers have a sanity check against too many
buffer allocations. However, the check is performed without a proper
lock and the allocation isn't serialized; this allows user to allocate
more memories than predefined max size.
Practically seen, this isn't really a big problem, as it's more or
less some "soft limit" as a sanity check, and it's not possible to
allocate unlimitedly. But it's still better to address this for more
consistent behavior.
The patch covers the size check in do_alloc_pages() with th
Wiz
CVE-2023-54072 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz
CVE-2023-54072 CVE-2023-54072 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2023-54072 :
Linux Kernel vulnerability analysis and mitigation
In the Linux kernel, the following vulnerability has been resolved:
ALSA: pcm: Fix potential data race at PCM memory allocation helpers
The PCM memory allocation helpers have a sanity check against too many
buffer allocations. However, the check is performed without a proper
lock and the allocation isn't serialized; this allows user to allocate
more memories than predefined max size.
Practically seen, this isn't really a big problem, as it's more or
less some "soft limit" as a sanity check, and it's not possible to
allocate unlimitedly. But it's still better to address this for more
consistent behavior.
The patch covers the size check in do_alloc_pages() with the
card->memory_mutex, and increases the allocated siz
https://git.kernel.org/stable/c/3eb4e47a94e3f76521d7d344696db61e6a9619c7https://git.kernel.org/stable/c/773ccad902f67583a58b5650a2f8d8daf2e76fachttps://git.kernel.org/stable/c/7e11c58b2620a22c67a5ae28d64ce383890ee9f4https://git.kernel.org/stable/c/7e1d1456c8db9949459c5a24e8845cfe92430b0fhttps://git.kernel.org/stable/c/a0ab49e7a758b488b2090171a75d50735c0876f6https://git.kernel.org/stable/c/bd55842ed998a622ba6611fe59b3358c9f76773d
2025-12-24
Published