In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Cancel pending work at closing a MIDI substream At closing a USB MIDI output substream, there might be still a pending work, which would eventually access the rawmidi runtime object that is being released. For fixing the race, make sure to cancel the pending work at closing.
| Product | Vendor | Version |
|---|---|---|
| Linux | Linux | Android-5.0.2 |
| Linux | Linux | 15.2(4)M4 |
| Linux | Linux | < 52.2 |
| Linux | Linux | 12.4.0 |