CyberRota Analysis
AI-GeneratedThe vulnerability affects the Linux kernel's Advanced Linux Sound Architecture (ALSA) subsystem, specifically in the `snd_seq_read()` function, which improperly handles the event pointer during the reading of queued variable-length events. This oversight allows a userspace sequencer client to potentially read sensitive kernel memory addresses, leading to information disclosure risks. Organizations utilizing Linux systems, particularly those leveraging ALSA for audio processing, should prioritize addressing this vulnerability to mitigate potential exploitation.
Original NVD Description
In the Linux kernel, the following vulnerability has been resolved: ALSA: seq: Clear variable event pointer on read snd_seq_read() copies a queued variable-length event header to userspace before expanding the payload. Queued variable-length events use SNDRV_SEQ_EXT_CHAINED internally, and data.ext.ptr points at the first extension cell. The read side strips SNDRV_SEQ_EXT_* bits from data.ext.len before the copy, but it leaves data.ext.ptr untouched. A userspace sequencer client can therefore write a direct variable event to itself and read back the extension-cell kernel address from the returned header. Clear the temporary header pointer before copy_to_user(). The original queued event remains unchanged and is still passed to snd_seq_expand_var_event(), so payload expansion keeps using the internal chain.