ALSA: usb-audio: Bound MIDI 2.0 endpoint descriptor scans

Summary

CVECVE-2026-52964
StatePUBLISHED
AssignerLinux
Source PriorityCVE Program / NVD first with legacy fallback
Published2026-06-24 17:17:06 UTC
Updated2026-06-24 17:17:06 UTC
DescriptionIn the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Bound MIDI 2.0 endpoint descriptor scans The USB MIDI 2.0 endpoint parser has the same descriptor walking pattern as the legacy MIDI parser. It validates bLength against bNumGrpTrmBlock before reading baAssoGrpTrmBlkID[], but not against the remaining bytes in the endpoint-extra scan. A malformed device can therefore make later baAssoGrpTrmBlkID[] reads consume bytes past the walked descriptor. Reject zero-length and overlong descriptors while walking endpoint extras.

Risk And Classification

EPSS: 0.001750000 probability, percentile 0.072030000 (date 2026-06-25)

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Linux Linux affected ff49d1df79aef7580fe3ac99d17c3f886655d080 fafc97bd01e4c737eaeafadfdadb1af4bbfa7307 git Not specified
CNA Linux Linux affected ff49d1df79aef7580fe3ac99d17c3f886655d080 a310b4bebda5e4a1b26520c0cc5145ccd6d617e2 git Not specified
CNA Linux Linux affected ff49d1df79aef7580fe3ac99d17c3f886655d080 f9c184a83574549a36ea69b755f650e57d164c78 git Not specified
CNA Linux Linux affected ff49d1df79aef7580fe3ac99d17c3f886655d080 17e76b19de1aff5ff4de64d269290bd1b07a01d3 git Not specified
CNA Linux Linux affected ff49d1df79aef7580fe3ac99d17c3f886655d080 918be519c7876329e1b6e2ea1c59f0b75e792dca git Not specified
CNA Linux Linux affected 6.5 Not specified
CNA Linux Linux unaffected 6.5 semver Not specified
CNA Linux Linux unaffected 6.6.141 6.6.* semver Not specified
CNA Linux Linux unaffected 6.12.91 6.12.* semver Not specified
CNA Linux Linux unaffected 6.18.33 6.18.* semver Not specified
CNA Linux Linux unaffected 7.0.10 7.0.* semver Not specified
CNA Linux Linux unaffected 7.1 * original_commit_for_fix Not specified

References

ReferenceSourceLinkTags
git.kernel.org/stable/c/f9c184a83574549a36ea69b755f650e57d164c78 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/17e76b19de1aff5ff4de64d269290bd1b07a01d3 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/a310b4bebda5e4a1b26520c0cc5145ccd6d617e2 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/fafc97bd01e4c737eaeafadfdadb1af4bbfa7307 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/918be519c7876329e1b6e2ea1c59f0b75e792dca 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis
© CVE.report 2026 |

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report