7.8

CVE-2026-80971

ALSA: bcd2000: clear the URB pointers on disconnect

In the Linux kernel, the following vulnerability has been resolved:

ALSA: bcd2000: clear the URB pointers on disconnect

bcd2000_free_usb_related_resources() frees both URBs and leaves the
pointers behind:

	usb_kill_urb(bcd2k->midi_out_urb);
	usb_kill_urb(bcd2k->midi_in_urb);

	usb_free_urb(bcd2k->midi_out_urb);
	usb_free_urb(bcd2k->midi_in_urb);

The rawmidi device outlives that call.  A substream that is still open
when the device is unplugged reaches bcd2000_midi_send() from the
trigger path on close.  That function writes to the freed URB and then
hands it to the USB core:

	bcd2k->midi_out_urb->transfer_buffer_length = BUFSIZE;
	...
	ret = usb_submit_urb(bcd2k->midi_out_urb, GFP_ATOMIC);

usb_kill_urb() does not stop a later submission either, so a submit that
races the disconnect can requeue the URB after it has been reaped.
midi_in_urb is exposed the same way: bcd2000_input_complete() resubmits
it from the completion handler.

KASAN on 7.2.0-rc5 (arm64):

  BUG: KASAN: slab-use-after-free in bcd2000_midi_send [snd_bcd2000]
  Write of size 4 at addr ffff00001827d388 by task bpoc/168
   __asan_store4
   bcd2000_midi_send [snd_bcd2000]
   bcd2000_midi_output_trigger [snd_bcd2000]
   snd_rawmidi_kernel_write1
   close_substream.part.0
  Freed by task 168:
   usb_free_urb
   bcd2000_disconnect [snd_bcd2000]

  BUG: KASAN: slab-use-after-free in usb_submit_urb
  Read of size 8 at addr ffff00001827d3b8 by task bpoc/168

Clear both pointers after freeing and test them on the paths that can
still run.  Poison the URBs before freeing them: usb_poison_urb() waits
for a running completion handler and rejects any later submission, so
after it returns the input path is quiesced and only the rawmidi trigger
path can still reach bcd2000_midi_send().  No unpoison is needed; the
URBs are freed on the next line.

Discovered by XBOW, triaged by Baul Lee <baul.lee@xbow.com>
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version b47a22290d581277be70e8a597824a4985d39e83
Version < 9af08677aa57debaca5b57c8045c52a83d3dd376
Status affected
Version b47a22290d581277be70e8a597824a4985d39e83
Version < 5a77febac6faf6da40fbb4555f703eeb91b58130
Status affected
Version b47a22290d581277be70e8a597824a4985d39e83
Version < 3c00004f134fc819f9d9e202c6a64acde0a1f8d0
Status affected
Version b47a22290d581277be70e8a597824a4985d39e83
Version < 6c07aad8a7c9ef8ebc4d03a964b882123a349a2e
Status affected
Version b47a22290d581277be70e8a597824a4985d39e83
Version < eb482a06791d6168beb8c78cc904ac5a5ed96a55
Status affected
Version b47a22290d581277be70e8a597824a4985d39e83
Version < 7df3194bdb7479cad9199889655a566a2c0c1d1b
Status affected
Version b47a22290d581277be70e8a597824a4985d39e83
Version < b06ebc7fe25a6af4a9f6e4a3d4236a4178ad4b01
Status affected
Version b47a22290d581277be70e8a597824a4985d39e83
Version < 459d3a64766f5ca2f1886daeaf24582831a5f5ab
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 3.16
Status affected
Version 0
Version < 3.16
Status unaffected
Version <= 5.10.*
Version 5.10.270
Status unaffected
Version <= 5.15.*
Version 5.15.221
Status unaffected
Version <= 6.1.*
Version 6.1.188
Status unaffected
Version <= 6.6.*
Version 6.6.157
Status unaffected
Version <= 6.12.*
Version 6.12.109
Status unaffected
Version <= 6.18.*
Version 6.18.50
Status unaffected
Version <= 7.2.*
Version 7.2.4
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.16% 0.054
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/eb482a06791d6168beb8c78cc904ac5a5ed96a55
https://git.kernel.org/stable/c/7df3194bdb7479cad9199889655a566a2c0c1d1b
https://git.kernel.org/stable/c/b06ebc7fe25a6af4a9f6e4a3d4236a4178ad4b01
https://git.kernel.org/stable/c/459d3a64766f5ca2f1886daeaf24582831a5f5ab
https://git.kernel.org/stable/c/3c00004f134fc819f9d9e202c6a64acde0a1f8d0
https://git.kernel.org/stable/c/5a77febac6faf6da40fbb4555f703eeb91b58130
https://git.kernel.org/stable/c/6c07aad8a7c9ef8ebc4d03a964b882123a349a2e
https://git.kernel.org/stable/c/9af08677aa57debaca5b57c8045c52a83d3dd376