CVE-2025-39997
published 2025-10-15CVE-2025-39997: In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: fix race condition to UAF in snd_usbmidi_free The previous commit…
PriorityP421low5.5
EPSS
0.19%
8.9th percentile
In the Linux kernel, the following vulnerability has been resolved:
ALSA: usb-audio: fix race condition to UAF in snd_usbmidi_free
The previous commit 0718a78f6a9f ("ALSA: usb-audio: Kill timer properly at
removal") patched a UAF issue caused by the error timer.
However, because the error timer kill added in this patch occurs after the
endpoint delete, a race condition to UAF still occurs, albeit rarely.
Additionally, since kill-cleanup for urb is also missing, freed memory can
be accessed in interrupt context related to urb, which can cause UAF.
Therefore, to prevent this, error timer and urb must be killed before
freeing the heap memory.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.16.11-1 (forky) | linux 6.16.11-1 (forky) |
| linux | linux | — | — |
| linux | linux | — | — |
| linux | linux | >= 06513dd6d32c37d0364db8488cfdf3e14da238a8 < e63f049c7764b615d1d50cb486745fa63372b42d | e63f049c7764b615d1d50cb486745fa63372b42d |
| linux | linux | >= 0718a78f6a9f04b88d0dc9616cc216b31c5f3cf1 < af600e7f5526d16146b3ae99f6ad57bfea79ca33 | af600e7f5526d16146b3ae99f6ad57bfea79ca33 |
| linux | linux | >= 0718a78f6a9f04b88d0dc9616cc216b31c5f3cf1 < 353d8c715cc951a980728133c9dd64ca5a0a186c | 353d8c715cc951a980728133c9dd64ca5a0a186c |
| linux | linux | >= 0718a78f6a9f04b88d0dc9616cc216b31c5f3cf1 < 9f2c0ac1423d5f267e7f1d1940780fc764b0fee3 | 9f2c0ac1423d5f267e7f1d1940780fc764b0fee3 |
| linux | linux | >= 6.1.167 < 6.1.175 | 6.1.175 |
| linux | linux | >= 6.15.3 < 6.16 | 6.16 |
| linux | linux | >= 647410a7da46067953a53c0d03f8680eff570959 < dc4874366cf6cf4a31d8fa4b7f0e2a5b2d7647ba | dc4874366cf6cf4a31d8fa4b7f0e2a5b2d7647ba |
| linux | linux | >= c611b9e55174e439dcd85a72969b43a95f3827a4 < 647d6b8d22be12842fde6ed0c56859ebc615f21e | 647d6b8d22be12842fde6ed0c56859ebc615f21e |
| linux | linux | >= efaf61052b8ff9ee8968912fbaf02c2847c78ede < e16985513e89466a236d2a7c202783b4dd0c5a46 | e16985513e89466a236d2a7c202783b4dd0c5a46 |
| linux | linux_kernel | >= 0 < 6.16.11-1 | 6.16.11-1 |
| linux | linux_kernel | >= 6.16.0 < 6.16.11 | 6.16.11 |
| linux | linux_kernel | >= 6.17.0 < 6.17.1 | 6.17.1 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2025-39997: In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: fix race condition to UAF in snd_usbmidi_free The previous commit
osv·2025-10-15
CVE-2025-39997 CVE-2025-39997: In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: fix race condition to UAF in snd_usbmidi_free The previous commit
In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: fix race condition to UAF in snd_usbmidi_free The previous commit 0718a78f6a9f ("ALSA: usb-audio: Kill timer properly at removal") patched a UAF issue caused by the error timer. However, because the error timer kill added in this patch occurs after the endpoint delete, a race condition to UAF still occurs, albeit rarely. Additionally, since kill-cleanup for urb is also missing, freed memory can be accessed in interrupt context related to urb, which can cause UAF. Therefore, to prevent this, error timer and urb must be killed before freeing the heap memory.
GHSA
GHSA-xc3r-7j5x-74w4: In the Linux kernel, the following vulnerability has been resolved:
ALSA: usb-audio: fix race condition to UAF in snd_usbmidi_free
The previous comm
ghsa_unreviewed·2025-10-15
CVE-2025-39997 GHSA-xc3r-7j5x-74w4: In the Linux kernel, the following vulnerability has been resolved:
ALSA: usb-audio: fix race condition to UAF in snd_usbmidi_free
The previous comm
In the Linux kernel, the following vulnerability has been resolved:
ALSA: usb-audio: fix race condition to UAF in snd_usbmidi_free
The previous commit 0718a78f6a9f ("ALSA: usb-audio: Kill timer properly at
removal") patched a UAF issue caused by the error timer.
However, because the error timer kill added in this patch occurs after the
endpoint delete, a race condition to UAF still occurs, albeit rarely.
Additionally, since kill-cleanup for urb is also missing, freed memory can
be accessed in interrupt context related to urb, which can cause UAF.
Therefore, to prevent this, error timer and urb must be killed before
freeing the heap memory.
OSV
ALSA: usb-audio: fix race condition to UAF in snd_usbmidi_free
osv·2025-10-15
CVE-2025-39997 ALSA: usb-audio: fix race condition to UAF in snd_usbmidi_free
ALSA: usb-audio: fix race condition to UAF in snd_usbmidi_free
In the Linux kernel, the following vulnerability has been resolved:
ALSA: usb-audio: fix race condition to UAF in snd_usbmidi_free
The previous commit 0718a78f6a9f ("ALSA: usb-audio: Kill timer properly at
removal") patched a UAF issue caused by the error timer.
However, because the error timer kill added in this patch occurs after the
endpoint delete, a race condition to UAF still occurs, albeit rarely.
Additionally, since kill-cleanup for urb is also missing, freed memory can
be accessed in interrupt context related to urb, which can cause UAF.
Therefore, to prevent this, error timer and urb must be killed before
freeing the heap memory.
Red Hat
kernel: Linux kernel: Use-After-Free in ALSA USB audio due to race condition
vendor_redhat·2025-10-15·CVSS 5.5
CVE-2025-39997 [LOW] CWE-476 kernel: Linux kernel: Use-After-Free in ALSA USB audio due to race condition
kernel: Linux kernel: Use-After-Free in ALSA USB audio due to race condition
In the Linux kernel, the following vulnerability has been resolved:
ALSA: usb-audio: fix race condition to UAF in snd_usbmidi_free
The previous commit 0718a78f6a9f ("ALSA: usb-audio: Kill timer properly at
removal") patched a UAF issue caused by the error timer.
However, because the error timer kill added in this patch occurs after the
endpoint delete, a race condition to UAF still occurs, albeit rarely.
Additionally, since kill-cleanup for urb is also missing, freed memory can
be accessed in interrupt context related to urb, which can cause UAF.
Therefore, to prevent this, error timer and urb must be killed before
freeing the heap memory.
A flaw was found in the Linux kernel's ALSA USB audio subsystem. A local
Debian
CVE-2025-39997: linux - In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-a...
vendor_debian·2025
CVE-2025-39997 [LOW] CVE-2025-39997: linux - In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-a...
In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: fix race condition to UAF in snd_usbmidi_free The previous commit 0718a78f6a9f ("ALSA: usb-audio: Kill timer properly at removal") patched a UAF issue caused by the error timer. However, because the error timer kill added in this patch occurs after the endpoint delete, a race condition to UAF still occurs, albeit rarely. Additionally, since kill-cleanup for urb is also missing, freed memory can be accessed in interrupt context related to urb, which can cause UAF. Therefore, to prevent this, error timer and urb must be killed before freeing the heap memory.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 6.16.11-1)
sid: resolved (fixed in 6.16.11-1)
trixie: resolved
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/353d8c715cc951a980728133c9dd64ca5a0a186chttps://git.kernel.org/stable/c/647d6b8d22be12842fde6ed0c56859ebc615f21ehttps://git.kernel.org/stable/c/9f2c0ac1423d5f267e7f1d1940780fc764b0fee3https://git.kernel.org/stable/c/af600e7f5526d16146b3ae99f6ad57bfea79ca33https://git.kernel.org/stable/c/dc4874366cf6cf4a31d8fa4b7f0e2a5b2d7647bahttps://git.kernel.org/stable/c/e16985513e89466a236d2a7c202783b4dd0c5a46https://git.kernel.org/stable/c/e63f049c7764b615d1d50cb486745fa63372b42d
2025-10-15
Published