CVE-2026-74504

Source
https://cve.org/CVERecord?id=CVE-2026-74504
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74504.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-74504
Downstream
Published
2026-08-15T12:27:28.829Z
Modified
2026-08-18T03:30:57.981880632Z
Summary
ALSA: seq: Fix division by zero in initialize_timer()
Details

In the Linux kernel, the following vulnerability has been resolved:

ALSA: seq: Fix division by zero in initialize_timer()

A userspace-driven ALSA timer (SNDUTIMER) lets an unprivileged user set the backing sndtimer's hardware resolution to an arbitrary 64-bit value via SNDRVTIMERIOCTLCREATE. sndutimer_create() only rejects zero.

When such a timer is bound to a sequencer queue, initialize_timer() computes the tick period as

tmr->ticks = 1000000000 / (r * freq);

where r is that user-controlled resolution and freq is the sequencer update rate in Hz, clamped to MINFREQUENCY..MAXFREQUENCY (10..6250). A resolution of 2^63 makes the 64-bit product r * freq wrap to zero for any even freq, including DEFAULT_FREQUENCY (1000), so the division faults with a divide-by-zero.

The division runs under tmr->lock with interrupts disabled, so the oops leaves the spinlock held and hangs the CPU. It is reachable by an unprivileged user with access to /dev/snd/timer and /dev/snd/seq.

Oops: divide error: 0000 [#1] SMP KASAN PTI CPU: 7 UID: 1000 PID: 456 Comm: alsasequtimer Not tainted 7.2.0-rc4+ RIP: 0010:initializetimer.constprop.0+0x20a/0x2d0 sndseqtimerstart+0x15e/0x2b0 sndseqcontrolqueue+0x56f/0xba0 sndseq_write+0x3e0/0x730

Reject an overflowing product with checkmuloverflow() and fall back to a single tick, which also avoids feeding a wrapped-but-nonzero divisor (e.g. 2^63 * 1000 mod 2^64 == 0, or other resolutions wrapping to a small value) into the period computation.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/74xxx/CVE-2026-74504.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
37745918e0e7575bc40f38da93a99b9fa6406224
Fixed
d0e19932875746118e298b4c974f3b2d4aeb16fc
Fixed
5260e195c53e898a4a76527d4bb2178f31795e78
Fixed
42c6543ff27ea280334244458d4f52ec7133cc05
Fixed
21e19688433452dfbbbe6b2bb670dea6eb92f0f6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74504.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.12.0
Fixed
6.12.103
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.44
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74504.json"