ALSA: usb-audio: fix OOB write in snd_usbmidi_us122l_output()
Summary
| CVE | CVE-2026-90033 |
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-16 11:17:16 UTC |
| Updated | 2026-09-16 11:17:16 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved:
ALSA: usb-audio: fix OOB write in snd_usbmidi_us122l_output()
The snd_usbmidi_us122l_output() picks a count of 2 on anything slower
than high speed and never relates it to ep->max_transfer. The URB
buffer holds exactly max_transfer bytes, so a device declaring a one
byte bulk endpoint takes two bytes from snd_rawmidi_transmit(), and the
memset that pads the rest computes 1 - 2 in int and wraps to SIZE_MAX.
Only 0x800e and 0x800f are pinned to nine bytes. The US-122MKII at
0x0644:0x8021 falls to the default and takes usb_maxpacket(), which the
USB core only clamps downward.
The akai and novation output ops in this file were given the same guard
recently. Do the same here. |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|
| CNA |
Linux |
Linux |
affected 030a07e441296c372f946cd4065b5d831d8dc40c 5538daf2a5cc80ac3f3e913c0db045d92d995d40 git |
Not specified |
| CNA |
Linux |
Linux |
affected 030a07e441296c372f946cd4065b5d831d8dc40c a441a8e52148c91c2f2a91f42e3b9bc961a13a4b git |
Not specified |
| CNA |
Linux |
Linux |
affected 030a07e441296c372f946cd4065b5d831d8dc40c 2dae0e3a59e31f78222279d544b98e747cd1fbff git |
Not specified |
| CNA |
Linux |
Linux |
affected 030a07e441296c372f946cd4065b5d831d8dc40c 1d4add2b832b56f81bb0eab065ec35c610343018 git |
Not specified |
| CNA |
Linux |
Linux |
affected 030a07e441296c372f946cd4065b5d831d8dc40c de6d252f115be887a701c09a05cdb076f3a590c9 git |
Not specified |
| CNA |
Linux |
Linux |
affected 030a07e441296c372f946cd4065b5d831d8dc40c 9392a2c346762ffee8edd1ba8bac50d2e24a2ed7 git |
Not specified |
| CNA |
Linux |
Linux |
affected 030a07e441296c372f946cd4065b5d831d8dc40c 9d81885d97cba7796d1f8edc88f2499c8296f5b9 git |
Not specified |
| CNA |
Linux |
Linux |
affected 030a07e441296c372f946cd4065b5d831d8dc40c e4637ce34607f1733a34a57294966d26b263e626 git |
Not specified |
| CNA |
Linux |
Linux |
affected 2.6.28 |
Not specified |
| CNA |
Linux |
Linux |
unaffected 2.6.28 semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 5.10.270 5.10.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 5.15.221 5.15.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.1.188 6.1.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.6.157 6.6.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.12.110 6.12.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.18.51 6.18.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.2.5 7.2.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.3-rc2 * original_commit_for_fix |
Not specified |
References
| Reference | Source | Link | Tags |
|---|
| git.kernel.org/stable/c/5538daf2a5cc80ac3f3e913c0db045d92d995d40 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/2dae0e3a59e31f78222279d544b98e747cd1fbff |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/9392a2c346762ffee8edd1ba8bac50d2e24a2ed7 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/1d4add2b832b56f81bb0eab065ec35c610343018 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/9d81885d97cba7796d1f8edc88f2499c8296f5b9 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/e4637ce34607f1733a34a57294966d26b263e626 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/de6d252f115be887a701c09a05cdb076f3a590c9 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/a441a8e52148c91c2f2a91f42e3b9bc961a13a4b |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.