CVE-2026-64029
7.8Linux · Kernel
A race condition flaw in the Linux kernel ALSA sequencer subsystem allows a local attacker with low privileges to achieve high confidentiality, integrity, and availability impact.
Executive summary
A concurrency vulnerability in the Linux kernel ALSA sequencer subsystem allows local attackers to achieve complete system compromise.
Vulnerability
This is a race condition vulnerability within the ALSA sequencer subsystem involving UMP output teardown and event input handling, requiring low local privileges to exploit.
Business impact
A successful exploit of this vulnerability can lead to full system compromise, allowing an attacker with local access to read or modify sensitive data, execute arbitrary code, and cause system crashes or denial of service. The CVSS score of 7.8 confirms a high severity rating due to the potential for complete confidentiality, integrity, and availability impact on the affected host.
Remediation
Immediate Action: Update the Linux kernel to version 6.6.142, 6.12.92, 6.18.34, 7.0.11, or later as specified by the vendor advisory.
Proactive Monitoring: Monitor system logs for kernel panics, segmentation faults, or unauthorized local access attempts.
Compensating Controls: Restrict local shell access and audit user accounts to minimize the risk of unauthorized users executing untrusted code on the system.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Administrators must prioritize updating vulnerable Linux kernel packages to the patched versions immediately to eliminate the underlying concurrency flaw. Applying these kernel updates prevents local attackers from leveraging race conditions to compromise host security.