ALSA: usb-audio: Clamp implicit feedback packet count to URB capacity

Summary

CVECVE-2026-98265
StatePUBLISHED
AssignerLinux
Source PriorityCVE Program / NVD first with legacy fallback
Published2026-10-06 09:18:15 UTC
Updated2026-10-06 09:18:15 UTC
DescriptionIn the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Clamp implicit feedback packet count to URB capacity data_ep_set_params() allocates each data URB for exactly u->packets isochronous frames, so urb->iso_frame_desc[] has u->packets slots and ctx->packets is the driver's only record of that limit. For an implicit feedback sink, snd_usb_queue_pending_output_urbs() overwrites it with the sync source's packet count, which is calculated independently from the capture endpoint's parameters. When that count is larger, prepare_playback_urb() and prepare_silent_urb() can write iso_frame_desc[] past the allocation; their existing bounds limit payload bytes, not the descriptor index. The reproducer uses a high-speed UAC2 device declaring bInterval 1 for implicit feedback capture (8 packets) and bInterval 4 for playback (1 packet). On the first capture completion after the stream starts, it accesses seven descriptors spanning 112 bytes beyond the one-packet URB: BUG: KASAN: slab-out-of-bounds in prepare_playback_urb (sound/usb/pcm.c:1560) Write of size 4 at addr ffff88801e696ad0 by task vhci_rx/178 prepare_playback_urb (sound/usb/pcm.c:1560) prepare_outbound_urb (sound/usb/endpoint.c:340) snd_usb_queue_pending_output_urbs (sound/usb/endpoint.c:501) snd_complete_urb (sound/usb/endpoint.c:1834) __usb_hcd_giveback_urb (drivers/usb/core/hcd.c:1657) usb_hcd_giveback_urb (drivers/usb/core/hcd.c:1741) vhci_rx_loop (drivers/usb/usbip/vhci_rx.c:107) kthread (kernel/kthread.c:436) The buggy address belongs to the object at ffff88801e696a00 which belongs to the cache kmalloc-256 of size 256 The buggy address is located 0 bytes to the right of allocated 208-byte region [ffff88801e696a00, ffff88801e696ad0) Record the allocated packet count per endpoint and clamp both the adopted count and the packet-size copy to it. Fold the Format Type II delimiter into urb_packs before the allocation loop so the recorded limit matches every URB.

Risk And Classification

EPSS: 0.001750000 probability, percentile 0.063790000 (date 2026-10-06)

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Linux Linux affected 32a1f64f8ff6e2c5391f5964baec697bce25b83c ad279ba0dc1781229f5b52f58d38d56960400e06 git Not specified
CNA Linux Linux affected e949fd266cfa1dcca7caa3faa698578c4ffd26d6 79c55a7b5d71cf2a6bbd4bd7698e1b10b70f813a git Not specified
CNA Linux Linux affected cf044e44190234a41a788de1cdbb6c21f4a52e1e ab77e3f453c5f2499c08d6e8e218501d25bab39e git Not specified
CNA Linux Linux affected cf044e44190234a41a788de1cdbb6c21f4a52e1e 76a986c980bb502c7688d605ac7a67fd257a9a1b git Not specified
CNA Linux Linux affected df75696e70c88b22ed1d8c9d515993a858c58fd0 git Not specified
CNA Linux Linux affected 3a74f6b46c01d9a816378cd83c327a59f61475ec git Not specified
CNA Linux Linux affected c26bde6301f20d9aafbfb7c2459a88c6a6ec178f git Not specified
CNA Linux Linux affected f6fbdf797e016fbf968dd54301026b182175985a git Not specified
CNA Linux Linux affected 6.12.75 6.12.112 semver Not specified
CNA Linux Linux affected 6.18.16 6.18.54 semver Not specified
CNA Linux Linux affected 5.15.202 5.16 semver Not specified
CNA Linux Linux affected 6.1.165 6.2 semver Not specified
CNA Linux Linux affected 6.6.128 6.7 semver Not specified
CNA Linux Linux affected 6.19.6 6.20 semver Not specified
CNA Linux Linux affected 7.0 Not specified
CNA Linux Linux unaffected 7.0 semver Not specified
CNA Linux Linux unaffected 6.12.112 6.12.* semver Not specified
CNA Linux Linux unaffected 6.18.54 6.18.* semver Not specified
CNA Linux Linux unaffected 7.2.8 7.2.* semver Not specified
CNA Linux Linux unaffected 7.3-rc4 * original_commit_for_fix Not specified

References

ReferenceSourceLinkTags
git.kernel.org/stable/c/79c55a7b5d71cf2a6bbd4bd7698e1b10b70f813a 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/76a986c980bb502c7688d605ac7a67fd257a9a1b 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/ad279ba0dc1781229f5b52f58d38d56960400e06 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/ab77e3f453c5f2499c08d6e8e218501d25bab39e 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report