HomeDefectsLIN1025-15229
Fixed

LIN1025-15229 : Security Advisory - linux - CVE-2026-46157

Created: May 29, 2026    Updated: Jun 10, 2026
Resolved Date: May 31, 2026
Found In Version: 10.25.33.2
Fix Version: 10.25.33.10
Severity: Standard
Applicable for: Wind River Linux LTS 25
Component/s: Kernel

Description

In the Linux kernel, the following vulnerability has been resolved:  ALSA: pcm: oss: Fix data race at accessing runtime.oss.trigger  Currently the runtime.oss.trigger field may be accessed concurrently without protection, which may lead to the data race.  And, in this case, it may lead to more severe problem because it's a bit field; as writing the data, it may overwrite other bit fields as well, which confuses the operation completely, as spotted by fuzzing.  Fix it by covering runtime.oss.trigger bit fled also with the existing params_lock mutex in both snd_pcm_oss_get_trigger() and snd_pcm_oss_poll().