ALSA: caiaq: fix out-of-bounds read in the Traktor Kontrol S4 input parser

Summary

CVECVE-2026-64487
StatePUBLISHED
AssignerLinux
Source PriorityCVE Program / NVD first with legacy fallback
Published2026-07-25 10:17:34 UTC
Updated2026-07-25 10:17:34 UTC
DescriptionIn the Linux kernel, the following vulnerability has been resolved: ALSA: caiaq: fix out-of-bounds read in the Traktor Kontrol S4 input parser snd_usb_caiaq_tks4_dispatch() decodes the Traktor Kontrol S4 input stream in fixed 16-byte (TKS4_MSGBLOCK_SIZE) message blocks. On every iteration it advances buf and subtracts the block size while looping on "while (len)". len is urb->actual_length. That value is supplied by the device and is not guaranteed to be a multiple of 16. When a final short block leaves len between 1 and 15, the loop runs once more, reads up to buf[15], and then does "len -= TKS4_MSGBLOCK_SIZE". As len is unsigned this underflows to a huge value. The loop then keeps iterating and walking buf far past the end of the 512-byte ep4_in_buf, reading out of bounds until a bogus block id happens to be hit. Iterate only while a full message block is available. This stops the unsigned underflow and silently drops any trailing partial block, which carries no complete control value anyway. The sibling endpoint-4 parsers are not affected. The Traktor Kontrol X1 and Maschine arms in snd_usb_caiaq_ep4_reply_dispatch() floor urb->actual_length before dispatching.

Risk And Classification

EPSS: 0.001840000 probability, percentile 0.083470000 (date 2026-07-28)

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Linux Linux affected 15c5ab607045e278ebf4d2ca4aea2250617d50ca de5f9edc705497b1b2c6b173b22f283486d2fd91 git Not specified
CNA Linux Linux affected 15c5ab607045e278ebf4d2ca4aea2250617d50ca 70d6d4cfa4ad09688aed2ec8a0cfa72c31f60334 git Not specified
CNA Linux Linux affected 15c5ab607045e278ebf4d2ca4aea2250617d50ca 884f575cc6acb136eb4a161d925147f85b59c27e git Not specified
CNA Linux Linux affected 15c5ab607045e278ebf4d2ca4aea2250617d50ca 05df59b9a61f7ca66548df079d306c41da23845d git Not specified
CNA Linux Linux affected 15c5ab607045e278ebf4d2ca4aea2250617d50ca 3cad86197c7bf8b45bb1d8adc1099d0913e80469 git Not specified
CNA Linux Linux affected 15c5ab607045e278ebf4d2ca4aea2250617d50ca a5fd3122283bf75c04f6414bf610100beb0565b0 git Not specified
CNA Linux Linux affected 15c5ab607045e278ebf4d2ca4aea2250617d50ca 0680413f2f10aab43878dd3db711a6a9e45bab7c git Not specified
CNA Linux Linux affected 15c5ab607045e278ebf4d2ca4aea2250617d50ca f7f3f9fd81e7adbaa12c2e62ee07f0e094a543fd git Not specified
CNA Linux Linux affected 2.6.37 Not specified
CNA Linux Linux unaffected 2.6.37 semver Not specified
CNA Linux Linux unaffected 5.10.261 5.10.* semver Not specified
CNA Linux Linux unaffected 5.15.212 5.15.* semver Not specified
CNA Linux Linux unaffected 6.1.178 6.1.* semver Not specified
CNA Linux Linux unaffected 6.6.145 6.6.* semver Not specified
CNA Linux Linux unaffected 6.12.96 6.12.* semver Not specified
CNA Linux Linux unaffected 6.18.39 6.18.* semver Not specified
CNA Linux Linux unaffected 7.1.4 7.1.* semver Not specified
CNA Linux Linux unaffected 7.2-rc1 * original_commit_for_fix Not specified

References

ReferenceSourceLinkTags
git.kernel.org/stable/c/0680413f2f10aab43878dd3db711a6a9e45bab7c 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/70d6d4cfa4ad09688aed2ec8a0cfa72c31f60334 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/05df59b9a61f7ca66548df079d306c41da23845d 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/a5fd3122283bf75c04f6414bf610100beb0565b0 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/de5f9edc705497b1b2c6b173b22f283486d2fd91 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/884f575cc6acb136eb4a161d925147f85b59c27e 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/f7f3f9fd81e7adbaa12c2e62ee07f0e094a543fd 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/3cad86197c7bf8b45bb1d8adc1099d0913e80469 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report