-

CVE-2026-98006

ALSA: caiaq: Decoupling ep1_in_urb in caiaq dev

In the Linux kernel, the following vulnerability has been resolved:

ALSA: caiaq: Decoupling ep1_in_urb in caiaq dev

The epq_in_urb object belonging to the caiaq device is coupled within
the struct snd_usb_caiaqdev. After usb_submit_urb(epq_in_urb, GFP_KERNEL)
executes successfully, epq_in_urb is successfully added to the urbp_list
queue of the dummy HCD driver (userspace specifies dummy_hcd as the HCD
layer driver for the caiaq USB device).

When init_card() calls snd_usb_caiaq_send_command() which subsequently
fails due to a timeout, and proceeds to call snd_card_free() to release
the card, the embedded ep1_in_urb object is also freed. When the dummy
HCD driver detects that the URB has been unlinked, it returns the URB
(by usb_hcd_giveback_urb()), which triggers [1].

Decouple the ep1_in_urb object from the struct snd_usb_caiaqdev and switch
to using a pointer instead. Separately allocate and manage the memory for
ep1_in_urb to prevent the release of the snd_card memory object from
interfering with it.

midi_out_urb has the same issue as ep1_in_urb and is handled in the same
way.

[1]
BUG: KASAN: slab-use-after-free in usb_free_urb+0x24/0x120 drivers/usb/core/urb.c:96
Write of size 4 at addr ffff88803cee1050 by task ktimers/1/29
Call Trace:
 usb_free_urb+0x24/0x120 drivers/usb/core/urb.c:96
 dummy_timer+0xaac/0x4d50 drivers/usb/gadget/udc/dummy_hcd.c:2019
 __run_hrtimer kernel/time/hrtimer.c:2067 [inline]
 __hrtimer_run_queues+0x3eb/0xaf0 kernel/time/hrtimer.c:2124
 hrtimer_run_softirq+0x1e1/0x2e0 kernel/time/hrtimer.c:2141

Allocated by task 36:
 snd_card_new+0x7b/0x110 sound/core/init.c:184
 create_card sound/usb/caiaq/device.c:429 [inline]
 snd_probe+0x236/0x1af0 sound/usb/caiaq/device.c:544

Freed by task 36:
 snd_card_free_when_closed sound/core/init.c:630 [inline]
 snd_card_free+0x138/0x1d0 sound/core/init.c:662
 snd_probe+0x162b/0x1af0 sound/usb/caiaq/device.c:553
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 523f1dce37434a9a6623bf46e7893e2b4b10ac3c
Version < a3bbd2845bc7188ae18548a591da1067af997e80
Status affected
Version 523f1dce37434a9a6623bf46e7893e2b4b10ac3c
Version < fbfbad728da2e95d6560e43266895de5c8e844b3
Status affected
Version 523f1dce37434a9a6623bf46e7893e2b4b10ac3c
Version < dbd3effcbdb85394d3c4bd5ee9df785a44303333
Status affected
Version 523f1dce37434a9a6623bf46e7893e2b4b10ac3c
Version < 671037b282eb7fe477136bd0130ffd9029eb8668
Status affected
Version 523f1dce37434a9a6623bf46e7893e2b4b10ac3c
Version < d6dd3c915b0d02457711d8fbaa60efc52144557f
Status affected
Version 523f1dce37434a9a6623bf46e7893e2b4b10ac3c
Version < 0c1b907d5db2f3508375776e5b78d69591aa5626
Status affected
Version 523f1dce37434a9a6623bf46e7893e2b4b10ac3c
Version < d41e6c1533f09b27fc562260d41417490d2b6084
Status affected
Version 523f1dce37434a9a6623bf46e7893e2b4b10ac3c
Version < 402a9d6aab7ac787ab075adeb562c3db8b8f564b
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 2.6.22
Status affected
Version 0
Version < 2.6.22
Status unaffected
Version <= 5.10.*
Version 5.10.271
Status unaffected
Version <= 5.15.*
Version 5.15.222
Status unaffected
Version <= 6.1.*
Version 6.1.189
Status unaffected
Version <= 6.6.*
Version 6.6.158
Status unaffected
Version <= 6.12.*
Version 6.12.111
Status unaffected
Version <= 6.18.*
Version 6.18.53
Status unaffected
Version <= 7.2.*
Version 7.2.7
Status unaffected
Version <= *
Version 7.3-rc3
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.17% 0.054
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/d6dd3c915b0d02457711d8fbaa60efc52144557f
https://git.kernel.org/stable/c/0c1b907d5db2f3508375776e5b78d69591aa5626
https://git.kernel.org/stable/c/d41e6c1533f09b27fc562260d41417490d2b6084
https://git.kernel.org/stable/c/402a9d6aab7ac787ab075adeb562c3db8b8f564b
https://git.kernel.org/stable/c/671037b282eb7fe477136bd0130ffd9029eb8668
https://git.kernel.org/stable/c/a3bbd2845bc7188ae18548a591da1067af997e80
https://git.kernel.org/stable/c/dbd3effcbdb85394d3c4bd5ee9df785a44303333
https://git.kernel.org/stable/c/fbfbad728da2e95d6560e43266895de5c8e844b3