ALSA: ump: fix double free of out_cvts on rawmidi error
Summary
| CVE | CVE-2026-74502 |
|---|---|
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-08-15 13:17:55 UTC |
| Updated | 2026-08-17 06:19:46 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved: ALSA: ump: fix double free of out_cvts on rawmidi error snd_ump_attach_legacy_rawmidi() allocates the legacy conversion array ump->out_cvts and, on the snd_rawmidi_new() error path, frees it with kfree() but leaves ump->out_cvts pointing at the freed memory. When the endpoint is later torn down, snd_ump_endpoint_free() frees ump->out_cvts a second time, resulting in a double free. The host snd-usb-audio driver attaches the legacy rawmidi for any USB MIDI 2.0 (UMP) device, so a device that makes snd_rawmidi_new() fail reaches this path on enumeration. Clear ump->out_cvts after freeing it on the error path so it is not freed again during teardown. Discovered by XBOW, triaged by Baul Lee <[email protected]> |
Risk And Classification
EPSS: 0.001680000 probability, percentile 0.065070000 (date 2026-08-17)
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Linux | Linux | affected 33cd7630782df2230529c3e8f1a6d0ae9cd6ab49 e84d2e53a05c78a04d1343eeb0f31a79456e79fc git | Not specified |
| CNA | Linux | Linux | affected 33cd7630782df2230529c3e8f1a6d0ae9cd6ab49 3302aaeac4f7ee6b775850db21d5f61064ce70ad git | Not specified |
| CNA | Linux | Linux | affected 33cd7630782df2230529c3e8f1a6d0ae9cd6ab49 032746c2dd9a4ea0774b04ac8a29e2ea628f106e git | Not specified |
| CNA | Linux | Linux | affected 33cd7630782df2230529c3e8f1a6d0ae9cd6ab49 c57001f55f97ef856fb6527e376c5c4a056a53a4 git | Not specified |
| CNA | Linux | Linux | affected 33cd7630782df2230529c3e8f1a6d0ae9cd6ab49 70c977815af0d997feb2d0c5d284d55689bf7051 git | Not specified |
| CNA | Linux | Linux | affected 6.5 | Not specified |
| CNA | Linux | Linux | unaffected 6.5 semver | Not specified |
| CNA | Linux | Linux | unaffected 6.6.151 6.6.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.12.103 6.12.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.18.44 6.18.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.1.8 7.1.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.2 * original_commit_for_fix | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| git.kernel.org/stable/c/70c977815af0d997feb2d0c5d284d55689bf7051 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/e84d2e53a05c78a04d1343eeb0f31a79456e79fc | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/c57001f55f97ef856fb6527e376c5c4a056a53a4 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/3302aaeac4f7ee6b775850db21d5f61064ce70ad | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/032746c2dd9a4ea0774b04ac8a29e2ea628f106e | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.