← All Advisories

CVE-2026-98086

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-98086

Key Details

CVECVE-2026-98086
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

ALSA: ump: do not touch legacy_rmidi before it exists

snd_ump_parse_endpoint() sets ump->parsed on every exit, including

error, before the caller attaches the legacy rawmidi device.

ump_handle_ep_name_msg() then treats parsed as "legacy_rmidi is live"

and calls ump_legacy_set_rawmidi_name(), which snprintf()s into

ump->legacy_rmidi->name. If a UMP packet arrives in that window

(IRQ path from snd_ump_receive), legacy_rmidi is still NULL

(KASAN null-ptr-deref in snprintf).

Guard the legacy helpers. parsed only means endpoint info was

parsed, not that legacy_rmidi exists. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-98086
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-98086