CyberRota Analysis
AI-GeneratedThe vulnerability affects the Linux kernel's Advanced Linux Sound Architecture (ALSA) subsystem, specifically in the handling of timer callbacks for slave instances when their master is closed. This flaw can lead to a use-after-free condition, potentially allowing an attacker to execute arbitrary code or cause a denial of service. Organizations using Linux systems, particularly those relying on ALSA for audio processing, should prioritize this issue to mitigate potential exploitation risks.
Original NVD Description
In the Linux kernel, the following vulnerability has been resolved: ALSA: timer: drain a slave's callback before its master detaches it snd_timer_close_locked() drains the closing instance's own in-flight callback (IFLG_CALLBACK) before freeing it, but not its slaves'. When a master instance is closed, remove_slave_links() clears each slave's ->timer; the slave's own close then reads timer == NULL and takes the branch that skips the drain entirely (snd_timer_stop_slave() also no-ops on a NULL timer). So a slave whose callback is still running when the master is closed is freed underneath the live callback, leading to use-after-free. Drain the slaves too before remove_slave_links() severs them. snd_timer_stop() has already taken this instance off the active list, so no new slave callback can be queued. Take the slaves off the ack list so a pending one can't fire either, then wait for any that is already in flight.