{"id":"CVE-2026-98316","title":"In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: bcd2000: Fix race between rawmidi and disconnect\n\nAlthough we tried to fix the potential UAF issues at USB disconnect on\nbcd2000 driver, there is still an overloo…","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: bcd2000: Fix race between rawmidi and disconnect\n\nAlthough we tried to fix the potential UAF issues at USB disconnect on\nbcd2000 driver, there is still an overloo…","severity":"none","vendor":"Linux","product":"Linux","affected":["Linux >= 3c00004f134fc819f9d9e202c6a64acde0a1f8d0 < 3b824930259d54f5047ce6b5c97bd20db2fc2b98","Linux >= 6c07aad8a7c9ef8ebc4d03a964b882123a349a2e < c83d6b0a65f7b71bbabcc91c045dfbffdff6ae76","Linux >= eb482a06791d6168beb8c78cc904ac5a5ed96a55 < 0a7ecf52cb59ed77ec525deb52c496ea8fba10b1","Linux >= 7df3194bdb7479cad9199889655a566a2c0c1d1b < 812ca56867bec3065c2a27f1ff5ce04e2a8bf4f0","Linux >= b06ebc7fe25a6af4a9f6e4a3d4236a4178ad4b01 < 9c8b6eff6e7505c128b615d9a1364ef66fa5c18e","Linux >= 459d3a64766f5ca2f1886daeaf24582831a5f5ab < 221253723dc58bb901c3f27a7659823e63fc598c","Linux 9af08677aa57debaca5b57c8045c52a83d3dd376","Linux 5a77febac6faf6da40fbb4555f703eeb91b58130","Linux >= 6.1.188 < 6.1.189","Linux >= 6.6.157 < 6.6.158","Linux >= 6.12.109 < 6.12.112","Linux >= 6.18.50 < 6.18.54","Linux >= 7.2.4 < 7.2.8","Linux >= 5.10.270 < 5.11","Linux >= 5.15.221 < 5.16","Linux 7.3-rc1"],"published":"2026-10-06","updated":"2026-10-06","sourceUpdated":"2026-10-06T09:18:23.363","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-98316","references":[{"url":"https://git.kernel.org/stable/c/0a7ecf52cb59ed77ec525deb52c496ea8fba10b1","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/221253723dc58bb901c3f27a7659823e63fc598c","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3b824930259d54f5047ce6b5c97bd20db2fc2b98","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/812ca56867bec3065c2a27f1ff5ce04e2a8bf4f0","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9c8b6eff6e7505c128b615d9a1364ef66fa5c18e","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/c83d6b0a65f7b71bbabcc91c045dfbffdff6ae76","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-06T08:50:17.411Z","slug":"CVE-2026-98316","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nALSA: bcd2000: Fix race between rawmidi and disconnect\n\nAlthough we tried to fix the potential UAF issues at USB disconnect on\nbcd2000 driver, there is still an overlooked case -- namely, when a\nrawmidi trigger callback has been already running at USB disconnect\nhandling, the in-flight function (e.g. bcd2000_midi_send()) could\nstill access the URB, because the previous URB NULL-check & clearance\nwas considered only for the URB complete callbacks, but not about the\nparallel rawmidi operations.\n\nFor addressing the race, this patch introduced a new spinlock that\ncovers each rawmidi operation as well as the rawmidi handling in the\ncomplete callback.  The URB is cleared with the lock, so it guarantees\nthat the pending rawmidi task already finished or a NULL check is\neffective.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}