---
id: CVE-2024-26654
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  ALSA: sh: aica: reorder cleanup operations to avoid UAF bugs

  The dreamcastcard->timer could schedule the spu_dma_work and the
  spu_dma_work could also arm the dreamcast…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  ALSA: sh: aica: reorder cleanup operations to avoid UAF bugs

  The dreamcastcard->timer could schedule the spu_dma_work and the
  spu_dma_work could also arm the dreamcast…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-416
vendor: linux
product: linux_kernel
affected:
  - 'linux_kernel >= 2.6.23, < 4.19.312'
  - 'linux_kernel >= 4.20, < 5.4.274'
  - 'linux_kernel >= 5.5, < 5.10.215'
  - 'linux_kernel >= 5.11, < 5.15.154'
  - 'linux_kernel >= 5.16, < 6.1.84'
  - 'linux_kernel >= 6.2, < 6.6.24'
  - 'linux_kernel >= 6.7, < 6.7.12'
  - 'linux_kernel >= 6.8, < 6.8.3'
  - linux_kernel = 6.9
  - debian_linux = 10.0
patched:
  - linux_kernel 6.8.3
published: '2024-04-01'
updated: '2026-08-04'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2024-26654'
references:
  - url: 'https://git.kernel.org/stable/c/051e0840ffa8ab25554d6b14b62c9ab9e4901457'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/3c907bf56905de7d27b329afaf59c2fb35d17b04'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/4206ad65a0ee76920041a755bd3c17c6ba59bba2'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/61d4787692c1fccdc268ffa7a891f9c149f50901'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/8c990221681688da34295d6d76cc2f5b963e83f5'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/9d66ae0e7bb78b54e1e0525456c6b54e1d132046'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/aa39e6878f61f50892ee2dd9d2176f72020be845'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/e955e8a7f38a856fc6534ba4e6bffd4d5cc80ac3'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/eeb2a2ca0b8de7e1c66afaf719529154e7dc60b2'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/051e0840ffa8ab25554d6b14b62c9ab9e4901457'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://git.kernel.org/stable/c/3c907bf56905de7d27b329afaf59c2fb35d17b04'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://git.kernel.org/stable/c/4206ad65a0ee76920041a755bd3c17c6ba59bba2'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://git.kernel.org/stable/c/61d4787692c1fccdc268ffa7a891f9c149f50901'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://git.kernel.org/stable/c/8c990221681688da34295d6d76cc2f5b963e83f5'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://git.kernel.org/stable/c/9d66ae0e7bb78b54e1e0525456c6b54e1d132046'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://git.kernel.org/stable/c/aa39e6878f61f50892ee2dd9d2176f72020be845'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://git.kernel.org/stable/c/e955e8a7f38a856fc6534ba4e6bffd4d5cc80ac3'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://git.kernel.org/stable/c/eeb2a2ca0b8de7e1c66afaf719529154e7dc60b2'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://lists.debian.org/debian-lts-announce/2024/06/msg00017.html'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00257
epssPercentile: 0.15554
ingestedAt: '2026-08-05T10:46:47.670Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

ALSA: sh: aica: reorder cleanup operations to avoid UAF bugs

The dreamcastcard->timer could schedule the spu_dma_work and the
spu_dma_work could also arm the dreamcastcard->timer.

When the snd_pcm_substream is closing, the aica_channel will be
deallocated. But it could still be dereferenced in the worker
thread. The reason is that del_timer() will return directly
regardless of whether the timer handler is running or not and
the worker could be rescheduled in the timer handler. As a result,
the UAF bug will happen. The racy situation is shown below:

      (Thread 1)                 |      (Thread 2)
snd_aicapcm_pcm_close()          |
 ...                             |  run_spu_dma() //worker
                                 |    mod_timer()
  flush_work()                   |
  del_timer()                    |  aica_period_elapsed() //timer
  kfree(dreamcastcard->channel)  |    schedule_work()
                                 |  run_spu_dma() //worker
  ...                            |    dreamcastcard->channel-> //USE

In order to mitigate this bug and other possible corner cases,
call mod_timer() conditionally in run_spu_dma(), then implement
PCM sync_stop op to cancel both the timer and worker. The sync_stop
op will be called from PCM core appropriately when needed.

## Affected

- `linux_kernel >= 2.6.23, < 4.19.312`
- `linux_kernel >= 4.20, < 5.4.274`
- `linux_kernel >= 5.5, < 5.10.215`
- `linux_kernel >= 5.11, < 5.15.154`
- `linux_kernel >= 5.16, < 6.1.84`
- `linux_kernel >= 6.2, < 6.6.24`
- `linux_kernel >= 6.7, < 6.7.12`
- `linux_kernel >= 6.8, < 6.8.3`
- `linux_kernel = 6.9`
- `debian_linux = 10.0`

## Remediation

Upgrade past the affected range:

- `linux_kernel 6.8.3`
