-

CVE-2026-80829

Medienbericht

ALSA: usb-audio: fix OOB write in snd_usbmidi_novation_output()

In the Linux kernel, the following vulnerability has been resolved:

ALSA: usb-audio: fix OOB write in snd_usbmidi_novation_output()

snd_usbmidi_novation_output() lays out a two-byte header at
transfer_buffer[0..1] and passes &transfer_buffer[2] together with a
length of ep->max_transfer - 2 to snd_rawmidi_transmit():

	count = snd_rawmidi_transmit(ep->ports[0].substream,
				     &transfer_buffer[2],
				     ep->max_transfer - 2);

ep->max_transfer comes from the output endpoint's wMaxPacketSize via
usb_maxpacket(). A malformed or malicious device can advertise a bulk
OUT endpoint with a wMaxPacketSize of 1 - the USB core only clamps this
value downwards - so ep->max_transfer becomes 1 and the count argument
becomes -1.

snd_rawmidi_transmit() passes the negative count on to
__snd_rawmidi_transmit_peek(), where "if (count1 > count) count1 = count"
leaves count1 negative; get_aligned_size() keeps it negative for a
byte-stream substream, so the following memcpy(buffer, ..., count1) runs
with a (size_t)-1 length and writes far past the transfer buffer, which
was allocated with usb_alloc_coherent(ep->max_transfer).

This is the same class of bug that was fixed for snd_usbmidi_akai_output()
in commit 0970274613fb ("ALSA: usb-audio: fix OOB write in
snd_usbmidi_akai_output()"); the novation output routine was left
unguarded. Bail out when the endpoint cannot hold the two-byte header
plus at least one payload byte.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < 558fc4485ecc704edfe7876d6cebae4738ff7ef8
Status affected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < 9c8212436631b0063cb021e9f58df438e3db84d0
Status affected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < e9c00d7533f99aa9833c4b598f47e3b3202fdb9a
Status affected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < 94e4562fcc81badd1d467ddfb88c27e4fae974c2
Status affected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < 7639ec9755d3ec0ec8cd7c0fdd2c3d3997434870
Status affected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < 91919b3b99ab7ce3d7dbb39fcf7c6c742a663c0c
Status affected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < 7f00dbddb51f4f74325cdc7c3f6b19fb3392481a
Status affected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < 1074c2306901b44ebcb83855583c6776e1e392ea
Status affected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < 1035a8f63bae28e498b0e7b5ac91d749844a7158
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 2.6.12
Status affected
Version 0
Version < 2.6.12
Status unaffected
Version <= 5.10.*
Version 5.10.269
Status unaffected
Version <= 5.15.*
Version 5.15.220
Status unaffected
Version <= 6.1.*
Version 6.1.187
Status unaffected
Version <= 6.6.*
Version 6.6.156
Status unaffected
Version <= 6.12.*
Version 6.12.108
Status unaffected
Version <= 6.18.*
Version 6.18.49
Status unaffected
Version <= 7.1.*
Version 7.1.13
Status unaffected
Version <= 7.2.*
Version 7.2.3
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.2% 0.093
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
08.09.2026 20:38
https://git.kernel.org/stable/c/558fc4485ecc704edfe7876d6cebae4738ff7ef8
https://git.kernel.org/stable/c/9c8212436631b0063cb021e9f58df438e3db84d0
https://git.kernel.org/stable/c/e9c00d7533f99aa9833c4b598f47e3b3202fdb9a
https://git.kernel.org/stable/c/94e4562fcc81badd1d467ddfb88c27e4fae974c2
https://git.kernel.org/stable/c/7639ec9755d3ec0ec8cd7c0fdd2c3d3997434870
https://git.kernel.org/stable/c/91919b3b99ab7ce3d7dbb39fcf7c6c742a663c0c
https://git.kernel.org/stable/c/7f00dbddb51f4f74325cdc7c3f6b19fb3392481a
https://git.kernel.org/stable/c/1074c2306901b44ebcb83855583c6776e1e392ea
https://git.kernel.org/stable/c/1035a8f63bae28e498b0e7b5ac91d749844a7158