{
  "affected": [
    {
      "ranges": [
        {
          "events": [
            {
              "introduced": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2"
            },
            {
              "fixed": "27f167e117eca310661fbcbacb352ea08face067"
            },
            {
              "fixed": "555d168bd98daa46daccc68c908201388c834293"
            },
            {
              "fixed": "8c869d5cf5affb20994bdbb60e7d46d65c91b55f"
            },
            {
              "fixed": "686c7a6af1eea8d2a919303e4c6bbec3de79dbdc"
            },
            {
              "fixed": "e1eee8f16628f8b6bcae0a366fd6a2dd65e71edd"
            },
            {
              "fixed": "d63f5a9f8121fb43c798056d7dd34c58f47185d7"
            },
            {
              "fixed": "0b349249d572633d7c8cdeb917623d1676a2b7c3"
            },
            {
              "fixed": "1e713f9bb2ac583521f06b0eb4e22440b1e3d078"
            }
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "type": "GIT"
        }
      ]
    },
    {
      "package": {
        "ecosystem": "Linux",
        "name": "Kernel"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "2.6.12"
            },
            {
              "fixed": "5.10.271"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "5.11.0"
            },
            {
              "fixed": "5.15.222"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "5.16.0"
            },
            {
              "fixed": "6.1.189"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.2.0"
            },
            {
              "fixed": "6.6.158"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.7.0"
            },
            {
              "fixed": "6.12.112"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.13.0"
            },
            {
              "fixed": "6.18.54"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.19.0"
            },
            {
              "fixed": "7.2.8"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "database_specific": {
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98314.json"
  },
  "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: pcm: set timer-\u003eprivate_data before registering the PCM timer\n\nsnd_pcm_timer_init() calls snd_device_register() to link the new\nstruct snd_timer into the global timer list while it still carries\nhw.c_resolution = snd_pcm_timer_resolution (and hw.start/hw.stop),\nand only afterwards sets timer-\u003eprivate_data = substream.\n\nOnce the timer is on the list under register_mutex, a concurrent\nreader can already reach it through the same mutex and invoke these\ncallbacks. /proc/asound/timers does this via c_resolution(), and\nsnd_timer_open()+snd_timer_start() reach start()/stop() the same way.\nAll three dereference timer-\u003eprivate_data, which for this brief\nwindow is NULL, giving a NULL-pointer dereference:\n\n  substream = timer-\u003eprivate_data;\n  return substream-\u003eruntime ? ...   // substream is NULL\n\nMove the private_data/private_free assignment before\nsnd_device_register() so the timer is never visible on the list\nwithout its private_data set. On the snd_device_register() failure\npath, private_free() (snd_pcm_timer_free()) can now run, but it only\ndoes substream-\u003etimer = NULL, which is already NULL at that point\nsince substream-\u003etimer is set to the new timer just once, after a\nsuccessful registration -- so the failure path stays safe.",
  "id": "CVE-2026-98314",
  "modified": "2026-10-08T02:30:59.829322593Z",
  "published": "2026-10-06T08:46:09.965Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/0b349249d572633d7c8cdeb917623d1676a2b7c3"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/1e713f9bb2ac583521f06b0eb4e22440b1e3d078"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/27f167e117eca310661fbcbacb352ea08face067"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/555d168bd98daa46daccc68c908201388c834293"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/686c7a6af1eea8d2a919303e4c6bbec3de79dbdc"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/8c869d5cf5affb20994bdbb60e7d46d65c91b55f"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/d63f5a9f8121fb43c798056d7dd34c58f47185d7"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/e1eee8f16628f8b6bcae0a366fd6a2dd65e71edd"
    },
    {
      "type": "ADVISORY",
      "url": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98314.json"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-98314"
    },
    {
      "type": "PACKAGE",
      "url": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"
    }
  ],
  "schema_version": "1.9.0",
  "summary": "ALSA: pcm: set timer-\u003eprivate_data before registering the PCM timer"
}