CVE-2025-23134: Linux Kernel

Medium severity, CVSS 5.5. EPSS: 0.1% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: ALSA: timer: Don't take register_mutex with copy_from/to_user() The infamous mmap_lock taken in copy_from/to_user() can be often problematic when it's called inside another mutex, as they might lead to deadlocks. In the case of ALSA timer code, the bad pattern is with guard(mutex)(&register_mutex) that covers copy_from/to_user() -- which was mistakenly introduced at converting to guard(), and it had been carefully worked around in the past. This patch fixes those pieces simply by moving copy_from/to_user() out of the register mutex lock again.

Affected products

  • Linux Linux Kernel: from 6.9, before 6.12.23 (fixed in 6.12.23); from 6.13, before 6.13.11 (fixed in 6.13.11); from 6.14, before 6.14.2 (fixed in 6.14.2)

Published 2025-04-16. Last modified 2026-06-17.