ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on each resubmission
Summary
| CVE | CVE-2026-64601 |
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-08-06 08:16:35 UTC |
| Updated | 2026-08-06 08:16:35 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved:
ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on each resubmission
In capture_urb_complete(), usb_anchor_urb() is called on every
completion callback, but the URB is already anchored from the
initial submission in tascam_trigger_start(). Each redundant call
corrupts the anchor's doubly-linked list and inflates the URB
refcount. When usb_kill_anchored_urbs() traverses the list during
stream stop / suspend / disconnect, the corrupted list leads to
use-after-free.
Remove the redundant usb_anchor_urb() from the resubmit path. |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|
| CNA |
Linux |
Linux |
affected c1bb0c13e430623c26543baae5bb9ae21139db87 16f14f55141d4c55c3f321f93c328fff7cd6860a git |
Not specified |
| CNA |
Linux |
Linux |
affected c1bb0c13e430623c26543baae5bb9ae21139db87 ab1db64912428cdf06a4f9542e16e0575e9ad59f git |
Not specified |
| CNA |
Linux |
Linux |
affected c1bb0c13e430623c26543baae5bb9ae21139db87 5cff1529a2f9b3461a7f5a6e36a86682fc290534 git |
Not specified |
| CNA |
Linux |
Linux |
affected 6.18 |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.18 semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.18.39 6.18.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.1.4 7.1.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.2-rc2 * original_commit_for_fix |
Not specified |
References
| Reference | Source | Link | Tags |
|---|
| git.kernel.org/stable/c/ab1db64912428cdf06a4f9542e16e0575e9ad59f |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/16f14f55141d4c55c3f321f93c328fff7cd6860a |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/5cff1529a2f9b3461a7f5a6e36a86682fc290534 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.