cbcvebase.
CVE-2025-39997
published 2025-10-15

CVE-2025-39997: In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: fix race condition to UAF in snd_usbmidi_free The previous commit…

PriorityP421low5.5
EPSS
0.19%
8.9th percentile
In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: fix race condition to UAF in snd_usbmidi_free The previous commit 0718a78f6a9f ("ALSA: usb-audio: Kill timer properly at removal") patched a UAF issue caused by the error timer. However, because the error timer kill added in this patch occurs after the endpoint delete, a race condition to UAF still occurs, albeit rarely. Additionally, since kill-cleanup for urb is also missing, freed memory can be accessed in interrupt context related to urb, which can cause UAF. Therefore, to prevent this, error timer and urb must be killed before freeing the heap memory.

Affected

15 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.16.11-1 (forky)linux 6.16.11-1 (forky)
linuxlinux
linuxlinux
linuxlinux>= 06513dd6d32c37d0364db8488cfdf3e14da238a8 < e63f049c7764b615d1d50cb486745fa63372b42de63f049c7764b615d1d50cb486745fa63372b42d
linuxlinux>= 0718a78f6a9f04b88d0dc9616cc216b31c5f3cf1 < af600e7f5526d16146b3ae99f6ad57bfea79ca33af600e7f5526d16146b3ae99f6ad57bfea79ca33
linuxlinux>= 0718a78f6a9f04b88d0dc9616cc216b31c5f3cf1 < 353d8c715cc951a980728133c9dd64ca5a0a186c353d8c715cc951a980728133c9dd64ca5a0a186c
linuxlinux>= 0718a78f6a9f04b88d0dc9616cc216b31c5f3cf1 < 9f2c0ac1423d5f267e7f1d1940780fc764b0fee39f2c0ac1423d5f267e7f1d1940780fc764b0fee3
linuxlinux>= 6.1.167 < 6.1.1756.1.175
linuxlinux>= 6.15.3 < 6.166.16
linuxlinux>= 647410a7da46067953a53c0d03f8680eff570959 < dc4874366cf6cf4a31d8fa4b7f0e2a5b2d7647badc4874366cf6cf4a31d8fa4b7f0e2a5b2d7647ba
linuxlinux>= c611b9e55174e439dcd85a72969b43a95f3827a4 < 647d6b8d22be12842fde6ed0c56859ebc615f21e647d6b8d22be12842fde6ed0c56859ebc615f21e
linuxlinux>= efaf61052b8ff9ee8968912fbaf02c2847c78ede < e16985513e89466a236d2a7c202783b4dd0c5a46e16985513e89466a236d2a7c202783b4dd0c5a46
linuxlinux_kernel>= 0 < 6.16.11-16.16.11-1
linuxlinux_kernel>= 6.16.0 < 6.16.116.16.11
linuxlinux_kernel>= 6.17.0 < 6.17.16.17.1
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.