Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CVE-2026-68200

7.8 · HIGH
Published Aug 10, 2026 EPSS 0.17% (7th pctl)

Overview

CVE-2026-68200 is a high-severity vulnerability. It was published on August 10, 2026 and has a CVSS 3.1 base score of 7.8 (HIGH).

This vulnerability has a CVSS 3.1 base score of 7.8, rated HIGH. It requires local or adjacent network access to exploit. Some level of privileges is required for exploitation.

Technical Description

In the Linux kernel, the following vulnerability has been resolved:

ALSA: timer: don't re-enter an instance callback that is still running

The userspace-driven timer (utimer) TRIGGER ioctl calls

snd_timer_interrupt() directly with no serialization, so two threads

triggering the same utimer can run snd_timer_interrupt() on one

snd_timer concurrently.

snd_timer_process_callbacks() drops timer->lock around each instance

callback and marks the in-flight callback with the single

SNDRV_TIMER_IFLG_CALLBACK bit; snd_timer_close_locked() waits on that

bit to drain an in-flight callback before freeing the instance. The bit

cannot represent two concurrent callbacks: when a second interrupt

re-queues an instance whose callback is still running, both run at once,

the first to finish clears the bit, and the close-path drain then frees

the instance (and its callback_data) while the other callback is still

live - a use-after-free reachable by any user able to open

/dev/snd/timer, both via a user ti

Remediation

Check the references section for vendor advisories, patches, and mitigation guidance. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

Frequently Asked Questions

What is CVE-2026-68200?

CVE-2026-68200 is a high-severity vulnerability. It was published on August 10, 2026 and has a CVSS 3.1 base score of 7.8 (HIGH).

How severe is CVE-2026-68200?

This vulnerability has a CVSS 3.1 base score of 7.8, rated HIGH. It requires local or adjacent network access to exploit. Some level of privileges is required for exploitation.

How do I fix or remediate CVE-2026-68200?

Check the references section for vendor advisories, patches, and mitigation guidance. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

How can CyberStrike help with CVE-2026-68200?

CyberStrike's AI-powered security agents can automatically detect CVE-2026-68200 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.