-
CVE-2026-80815
- EPSS 0.17%
- Veröffentlicht 04.09.2026 15:13:35
- Zuletzt bearbeitet 04.09.2026 16:18:09
- Erkennungen
ALSA: scarlett2: Use a private URB for the notification endpoint
In the Linux kernel, the following vulnerability has been resolved: ALSA: scarlett2: Use a private URB for the notification endpoint scarlett2_init_notify() used mixer->urb, which snd_usb_mixer_status_create() allocates for the UAC2 status interrupt endpoint and mixer.c manages. On a device with that endpoint, the "already in use" check fires on the status URB and returns 0 for success without doing anything. No notification URB is submitted, and cmd_done is left zeroed because it is initialised past that check and nowhere else. scarlett2_usb_init() then issues SCARLETT2_USB_INIT_1 and wait_for_completion_timeout() would crash adding to the zeroed wait.head. Use a separate URB in scarlett2_data, as done for FCP, and initialise cmd_done in scarlett2_init_private(). mixer.c was also freeing the URB in snd_usb_mixer_free() and resubmitting it in snd_usb_mixer_activate(), so scarlett2 must now do both: add scarlett2_cleanup_urb(), called from private_free and private_suspend, and a private_resume callback to re-establish the URB after resume. scarlett2_init_notify() is reached from there, and the URB kill path in scarlett2_notify() completes cmd_done, leaving a stale count that would satisfy the next command's wait before the device ACKs. Use reinit_completion() to clear it. Also free the URB if the transfer buffer allocation fails, and both if usb_submit_urb() fails. Move scarlett2_init_notify() up next to scarlett2_cleanup_urb() so scarlett2_init_private() can reference it without a forward declaration.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
1b65088958cadab04d5d34a8615e2466b1b48ecb
Version <
013448eb7b0d0b91d6168685dab10e9b41baa825
Status
affected
Version
1b65088958cadab04d5d34a8615e2466b1b48ecb
Version <
4305e4b52acc0ca67dcfdf8f73dd943dab508ae8
Status
affected
Version
1b65088958cadab04d5d34a8615e2466b1b48ecb
Version <
04df0232a6976845cd9c9e83b6c26215759be667
Status
affected
Version
1b65088958cadab04d5d34a8615e2466b1b48ecb
Version <
ecd2f83a4ddc078901e7104144cb6c5e5db3b7cf
Status
affected
Version
1b65088958cadab04d5d34a8615e2466b1b48ecb
Version <
cd17d6ff7b7d2b1dd9bcc80ae7b4a83773f918c6
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
6.10
Status
affected
Version
0
Version <
6.10
Status
unaffected
Version <=
6.12.*
Version
6.12.106
Status
unaffected
Version <=
6.18.*
Version
6.18.47
Status
unaffected
Version <=
7.1.*
Version
7.1.11
Status
unaffected
Version <=
7.2.*
Version
7.2.1
Status
unaffected
Version <=
*
Version
7.3-rc1
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.17% | 0.063 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|
https://git.kernel.org/stable/c/013448eb7b0d0b91d6168685dab10e9b41baa825
https://git.kernel.org/stable/c/4305e4b52acc0ca67dcfdf8f73dd943dab508ae8
https://git.kernel.org/stable/c/04df0232a6976845cd9c9e83b6c26215759be667
https://git.kernel.org/stable/c/ecd2f83a4ddc078901e7104144cb6c5e5db3b7cf
https://git.kernel.org/stable/c/cd17d6ff7b7d2b1dd9bcc80ae7b4a83773f918c6