ALSA: usb-audio: Bound MIDI endpoint descriptor scans
Summary
| CVE | CVE-2026-52963 |
|---|---|
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-06-24 17:17:06 UTC |
| Updated | 2026-06-24 17:17:06 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Bound MIDI endpoint descriptor scans snd_usbmidi_get_ms_info() validates the internal MIDIStreaming endpoint descriptor size before using baAssocJackID[], but the descriptor walker can still return a class-specific endpoint descriptor whose bLength exceeds the remaining bytes in the endpoint-extra scan. That leaves later flexible-array reads bounded by bLength, but not by the remaining bytes in the endpoint-extra scan. Stop walking when bLength is zero or extends past the remaining endpoint-extra scan. |
Risk And Classification
EPSS: 0.001840000 probability, percentile 0.081760000 (date 2026-06-25)
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Linux | Linux | affected 5c6cd7021a05a02fcf37f360592d7c18d4d807fb e2f1260a056eb3215c13c48c5378f3e4112dc3af git | Not specified |
| CNA | Linux | Linux | affected 5c6cd7021a05a02fcf37f360592d7c18d4d807fb c65b137d351e21cbc5630e73ef0eb1e1d75f5b20 git | Not specified |
| CNA | Linux | Linux | affected 5c6cd7021a05a02fcf37f360592d7c18d4d807fb 728ab0c72e49ca27185067984cd565425eb69b2e git | Not specified |
| CNA | Linux | Linux | affected 5c6cd7021a05a02fcf37f360592d7c18d4d807fb 3d3b2b01a3e73828e201ece96f863e7a3e0cdc6e git | Not specified |
| CNA | Linux | Linux | affected 5c6cd7021a05a02fcf37f360592d7c18d4d807fb a0226560540c16717efcceaf15c862cf115b01d3 git | Not specified |
| CNA | Linux | Linux | affected 5c6cd7021a05a02fcf37f360592d7c18d4d807fb 09141583bd97f4bbd7358e29fd138fe798467cdb git | Not specified |
| CNA | Linux | Linux | affected 5c6cd7021a05a02fcf37f360592d7c18d4d807fb c59159ce10e75b568cd0d4b29efcb0fb0ddecc94 git | Not specified |
| CNA | Linux | Linux | affected 5c6cd7021a05a02fcf37f360592d7c18d4d807fb d6854daa67be623860f4e1873fd3d3c275aba4ed git | Not specified |
| CNA | Linux | Linux | affected 9e0c71f2f633b0442661966228827d1a33df485f git | Not specified |
| CNA | Linux | Linux | affected 0868bc5654c07628c421547f0821650a8c2cb8f3 git | Not specified |
| CNA | Linux | Linux | affected 78483c1c7741ffa72991d93d19a75bfdcc2cbf57 git | Not specified |
| CNA | Linux | Linux | affected 65d95462001c6ccd9bc9499c1fc9a90eca9de496 git | Not specified |
| CNA | Linux | Linux | affected ca767cf0152d18fc299cde85b18d1f46ac21e1ba git | Not specified |
| CNA | Linux | Linux | affected 4.4.238 4.5 semver | Not specified |
| CNA | Linux | Linux | affected 4.9.238 4.10 semver | Not specified |
| CNA | Linux | Linux | affected 4.14.200 4.15 semver | Not specified |
| CNA | Linux | Linux | affected 4.19.149 4.20 semver | Not specified |
| CNA | Linux | Linux | affected 5.4.69 5.5 semver | Not specified |
| CNA | Linux | Linux | affected 5.7 | Not specified |
| CNA | Linux | Linux | unaffected 5.7 semver | Not specified |
| CNA | Linux | Linux | unaffected 5.10.258 5.10.* semver | Not specified |
| CNA | Linux | Linux | unaffected 5.15.209 5.15.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.1.175 6.1.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.6.141 6.6.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.12.91 6.12.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.18.33 6.18.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.0.10 7.0.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.1 * original_commit_for_fix | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| git.kernel.org/stable/c/09141583bd97f4bbd7358e29fd138fe798467cdb | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/3d3b2b01a3e73828e201ece96f863e7a3e0cdc6e | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/728ab0c72e49ca27185067984cd565425eb69b2e | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/d6854daa67be623860f4e1873fd3d3c275aba4ed | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/c59159ce10e75b568cd0d4b29efcb0fb0ddecc94 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/e2f1260a056eb3215c13c48c5378f3e4112dc3af | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/c65b137d351e21cbc5630e73ef0eb1e1d75f5b20 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/a0226560540c16717efcceaf15c862cf115b01d3 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.