{"api_version":"1","generated_at":"2026-08-18T05:18:37+00:00","cve":"CVE-2026-72443","urls":{"html":"https://cve.report/CVE-2026-72443","api":"https://cve.report/api/cve/CVE-2026-72443.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-72443","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-72443"},"summary":{"title":"ALSA: usb-audio: Kill MIDI 2.0 URBs before freeing endpoints","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: usb-audio: Kill MIDI 2.0 URBs before freeing endpoints\n\nMIDI 2.0 input URBs are started during snd_usb_midi_v2_create(). A\nlater setup failure can still jump to snd_usb_midi_v2_free(), which\ncurrently frees each endpoint and its coherent URB buffers without first\nstopping the submitted URBs. A completion can then dereference the\nembedded URB context and endpoint state after they have been freed, or\ntry to resubmit from the stale endpoint.\n\nThis was observed as a KASAN slab-use-after-free in\ninput_urb_complete().\n\nThe buggy scenario involves two paths, with each column showing the order\nwithin that path:\n\nprobe error path:                         USB completion path:\n1. start_input_streams() submits          1. The HCD still owns a\n   input URBs.                               submitted input URB.\n2. A later setup helper returns           2. input_urb_complete() runs\n   an error.                                 with urb->context in ep.\n3. snd_usb_midi_v2_free() frees           3. The completion reads ep\n   endpoint storage and URB buffers.         state and can requeue URBs.\n\nMake the endpoint destructor follow the same teardown ordering used for\ndisconnect when the endpoint has not already been disconnected: publish\nep->disconnected, kill the URBs synchronously, and drain the endpoint\nbefore freeing URB buffers and endpoint storage. The guard avoids\nrepeating the stop sequence after the normal\nsnd_usb_midi_v2_disconnect_all() path, while still synchronizing the\ndirect MIDI 2.0 create-error free path.\n\nValidation reproduced this kernel report:\nBUG: KASAN: slab-use-after-free in input_urb_complete+0x37/0x1b0\nWorkqueue: usb_hub_wq hub_event\nRIP: 0010:_raw_spin_unlock_irq+0x2e/0x50\nRead of size 8\nCall trace:\n  dump_stack_lvl+0x77/0xb0\n  print_report+0xce/0x5f0\n  input_urb_complete+0x37/0x1b0 (sound/usb/midi2.c:186)\n  srso_alias_return_thunk+0x5/0xfbef5\n  __virt_addr_valid+0x19f/0x330\n  kasan_report+0xe0/0x110\n  __usb_hcd_giveback_urb+0x112/0x1d0\n  dummy_timer+0xaaa/0x19a0\n  lock_is_held_type+0x9a/0x110\n  __lock_acquire+0x467/0x28b0\n  mark_held_locks+0x40/0x70\n  _raw_spin_unlock_irqrestore+0x44/0x60\n  lockdep_hardirqs_on_prepare+0xbb/0x1a0\n  __hrtimer_run_queues+0x101/0x520\n  hrtimer_run_softirq+0xd0/0x130\n  handle_softirqs+0x15b/0x670\n  __irq_exit_rcu+0xd0/0x170\n  irq_exit_rcu+0xe/0x20\n  sysvec_apic_timer_interrupt+0x6c/0x80\n  asm_sysvec_apic_timer_interrupt+0x1a/0x20","state":"PUBLISHED","assigner":"Linux","published_at":"2026-08-15 06:22:18","updated_at":"2026-08-17 06:19:11"},"problem_types":[],"metrics":[],"references":[{"url":"https://git.kernel.org/stable/c/f199c8a8bdd54296d3458777e70fe82a78bd9817","name":"https://git.kernel.org/stable/c/f199c8a8bdd54296d3458777e70fe82a78bd9817","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/4c16176fc11a61b7545464cb47c98b0c8a055fcb","name":"https://git.kernel.org/stable/c/4c16176fc11a61b7545464cb47c98b0c8a055fcb","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/68286258698e15fe75073fb8d017003f8e493db1","name":"https://git.kernel.org/stable/c/68286258698e15fe75073fb8d017003f8e493db1","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/bcdd5a7363bdd287253c406a9c0205f5722058e7","name":"https://git.kernel.org/stable/c/bcdd5a7363bdd287253c406a9c0205f5722058e7","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/3d961032a6e58fa485b3a4c0fe0f649334d887de","name":"https://git.kernel.org/stable/c/3d961032a6e58fa485b3a4c0fe0f649334d887de","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-72443","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-72443","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected d9c99876868c861afd0e9ce2cea407bbc446b3c9 bcdd5a7363bdd287253c406a9c0205f5722058e7 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected d9c99876868c861afd0e9ce2cea407bbc446b3c9 3d961032a6e58fa485b3a4c0fe0f649334d887de git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected d9c99876868c861afd0e9ce2cea407bbc446b3c9 4c16176fc11a61b7545464cb47c98b0c8a055fcb git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected d9c99876868c861afd0e9ce2cea407bbc446b3c9 68286258698e15fe75073fb8d017003f8e493db1 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected d9c99876868c861afd0e9ce2cea407bbc446b3c9 f199c8a8bdd54296d3458777e70fe82a78bd9817 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 6.5","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.5 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.6.145 6.6.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.12.97 6.12.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.18.40 6.18.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.1.5 7.1.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.2 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"72443","cve":"CVE-2026-72443","epss":"0.001750000","percentile":"0.073180000","score_date":"2026-08-17","updated_at":"2026-08-18 00:11:47"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["sound/usb/midi2.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"bcdd5a7363bdd287253c406a9c0205f5722058e7","status":"affected","version":"d9c99876868c861afd0e9ce2cea407bbc446b3c9","versionType":"git"},{"lessThan":"3d961032a6e58fa485b3a4c0fe0f649334d887de","status":"affected","version":"d9c99876868c861afd0e9ce2cea407bbc446b3c9","versionType":"git"},{"lessThan":"4c16176fc11a61b7545464cb47c98b0c8a055fcb","status":"affected","version":"d9c99876868c861afd0e9ce2cea407bbc446b3c9","versionType":"git"},{"lessThan":"68286258698e15fe75073fb8d017003f8e493db1","status":"affected","version":"d9c99876868c861afd0e9ce2cea407bbc446b3c9","versionType":"git"},{"lessThan":"f199c8a8bdd54296d3458777e70fe82a78bd9817","status":"affected","version":"d9c99876868c861afd0e9ce2cea407bbc446b3c9","versionType":"git"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["sound/usb/midi2.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"6.5"},{"lessThan":"6.5","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"6.6.*","status":"unaffected","version":"6.6.145","versionType":"semver"},{"lessThanOrEqual":"6.12.*","status":"unaffected","version":"6.12.97","versionType":"semver"},{"lessThanOrEqual":"6.18.*","status":"unaffected","version":"6.18.40","versionType":"semver"},{"lessThanOrEqual":"7.1.*","status":"unaffected","version":"7.1.5","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.2","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.6.145","versionStartIncluding":"6.5","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.12.97","versionStartIncluding":"6.5","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.18.40","versionStartIncluding":"6.5","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.1.5","versionStartIncluding":"6.5","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2","versionStartIncluding":"6.5","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: usb-audio: Kill MIDI 2.0 URBs before freeing endpoints\n\nMIDI 2.0 input URBs are started during snd_usb_midi_v2_create(). A\nlater setup failure can still jump to snd_usb_midi_v2_free(), which\ncurrently frees each endpoint and its coherent URB buffers without first\nstopping the submitted URBs. A completion can then dereference the\nembedded URB context and endpoint state after they have been freed, or\ntry to resubmit from the stale endpoint.\n\nThis was observed as a KASAN slab-use-after-free in\ninput_urb_complete().\n\nThe buggy scenario involves two paths, with each column showing the order\nwithin that path:\n\nprobe error path:                         USB completion path:\n1. start_input_streams() submits          1. The HCD still owns a\n   input URBs.                               submitted input URB.\n2. A later setup helper returns           2. input_urb_complete() runs\n   an error.                                 with urb->context in ep.\n3. snd_usb_midi_v2_free() frees           3. The completion reads ep\n   endpoint storage and URB buffers.         state and can requeue URBs.\n\nMake the endpoint destructor follow the same teardown ordering used for\ndisconnect when the endpoint has not already been disconnected: publish\nep->disconnected, kill the URBs synchronously, and drain the endpoint\nbefore freeing URB buffers and endpoint storage. The guard avoids\nrepeating the stop sequence after the normal\nsnd_usb_midi_v2_disconnect_all() path, while still synchronizing the\ndirect MIDI 2.0 create-error free path.\n\nValidation reproduced this kernel report:\nBUG: KASAN: slab-use-after-free in input_urb_complete+0x37/0x1b0\nWorkqueue: usb_hub_wq hub_event\nRIP: 0010:_raw_spin_unlock_irq+0x2e/0x50\nRead of size 8\nCall trace:\n  dump_stack_lvl+0x77/0xb0\n  print_report+0xce/0x5f0\n  input_urb_complete+0x37/0x1b0 (sound/usb/midi2.c:186)\n  srso_alias_return_thunk+0x5/0xfbef5\n  __virt_addr_valid+0x19f/0x330\n  kasan_report+0xe0/0x110\n  __usb_hcd_giveback_urb+0x112/0x1d0\n  dummy_timer+0xaaa/0x19a0\n  lock_is_held_type+0x9a/0x110\n  __lock_acquire+0x467/0x28b0\n  mark_held_locks+0x40/0x70\n  _raw_spin_unlock_irqrestore+0x44/0x60\n  lockdep_hardirqs_on_prepare+0xbb/0x1a0\n  __hrtimer_run_queues+0x101/0x520\n  hrtimer_run_softirq+0xd0/0x130\n  handle_softirqs+0x15b/0x670\n  __irq_exit_rcu+0xd0/0x170\n  irq_exit_rcu+0xe/0x20\n  sysvec_apic_timer_interrupt+0x6c/0x80\n  asm_sysvec_apic_timer_interrupt+0x1a/0x20"}],"providerMetadata":{"dateUpdated":"2026-08-17T05:14:44.380Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/bcdd5a7363bdd287253c406a9c0205f5722058e7"},{"url":"https://git.kernel.org/stable/c/3d961032a6e58fa485b3a4c0fe0f649334d887de"},{"url":"https://git.kernel.org/stable/c/4c16176fc11a61b7545464cb47c98b0c8a055fcb"},{"url":"https://git.kernel.org/stable/c/68286258698e15fe75073fb8d017003f8e493db1"},{"url":"https://git.kernel.org/stable/c/f199c8a8bdd54296d3458777e70fe82a78bd9817"}],"title":"ALSA: usb-audio: Kill MIDI 2.0 URBs before freeing endpoints","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-72443","datePublished":"2026-08-15T05:56:54.601Z","dateReserved":"2026-08-09T03:40:39.930Z","dateUpdated":"2026-08-17T05:14:44.380Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-08-15 06:22:18","lastModifiedDate":"2026-08-17 06:19:11","problem_types":[],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"72443","Ordinal":"1","Title":"ALSA: usb-audio: Kill MIDI 2.0 URBs before freeing endpoints","CVE":"CVE-2026-72443","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"72443","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: usb-audio: Kill MIDI 2.0 URBs before freeing endpoints\n\nMIDI 2.0 input URBs are started during snd_usb_midi_v2_create(). A\nlater setup failure can still jump to snd_usb_midi_v2_free(), which\ncurrently frees each endpoint and its coherent URB buffers without first\nstopping the submitted URBs. A completion can then dereference the\nembedded URB context and endpoint state after they have been freed, or\ntry to resubmit from the stale endpoint.\n\nThis was observed as a KASAN slab-use-after-free in\ninput_urb_complete().\n\nThe buggy scenario involves two paths, with each column showing the order\nwithin that path:\n\nprobe error path:                         USB completion path:\n1. start_input_streams() submits          1. The HCD still owns a\n   input URBs.                               submitted input URB.\n2. A later setup helper returns           2. input_urb_complete() runs\n   an error.                                 with urb->context in ep.\n3. snd_usb_midi_v2_free() frees           3. The completion reads ep\n   endpoint storage and URB buffers.         state and can requeue URBs.\n\nMake the endpoint destructor follow the same teardown ordering used for\ndisconnect when the endpoint has not already been disconnected: publish\nep->disconnected, kill the URBs synchronously, and drain the endpoint\nbefore freeing URB buffers and endpoint storage. The guard avoids\nrepeating the stop sequence after the normal\nsnd_usb_midi_v2_disconnect_all() path, while still synchronizing the\ndirect MIDI 2.0 create-error free path.\n\nValidation reproduced this kernel report:\nBUG: KASAN: slab-use-after-free in input_urb_complete+0x37/0x1b0\nWorkqueue: usb_hub_wq hub_event\nRIP: 0010:_raw_spin_unlock_irq+0x2e/0x50\nRead of size 8\nCall trace:\n  dump_stack_lvl+0x77/0xb0\n  print_report+0xce/0x5f0\n  input_urb_complete+0x37/0x1b0 (sound/usb/midi2.c:186)\n  srso_alias_return_thunk+0x5/0xfbef5\n  __virt_addr_valid+0x19f/0x330\n  kasan_report+0xe0/0x110\n  __usb_hcd_giveback_urb+0x112/0x1d0\n  dummy_timer+0xaaa/0x19a0\n  lock_is_held_type+0x9a/0x110\n  __lock_acquire+0x467/0x28b0\n  mark_held_locks+0x40/0x70\n  _raw_spin_unlock_irqrestore+0x44/0x60\n  lockdep_hardirqs_on_prepare+0xbb/0x1a0\n  __hrtimer_run_queues+0x101/0x520\n  hrtimer_run_softirq+0xd0/0x130\n  handle_softirqs+0x15b/0x670\n  __irq_exit_rcu+0xd0/0x170\n  irq_exit_rcu+0xe/0x20\n  sysvec_apic_timer_interrupt+0x6c/0x80\n  asm_sysvec_apic_timer_interrupt+0x1a/0x20","Type":"Description","Title":"ALSA: usb-audio: Kill MIDI 2.0 URBs before freeing endpoints"}]}}}