-

CVE-2026-98265

ALSA: usb-audio: Clamp implicit feedback packet count to URB capacity

In the Linux kernel, the following vulnerability has been resolved:

ALSA: usb-audio: Clamp implicit feedback packet count to URB capacity

data_ep_set_params() allocates each data URB for exactly u->packets
isochronous frames, so urb->iso_frame_desc[] has u->packets slots and
ctx->packets is the driver's only record of that limit. For an implicit
feedback sink, snd_usb_queue_pending_output_urbs() overwrites it with the
sync source's packet count, which is calculated independently from the
capture endpoint's parameters. When that count is larger,
prepare_playback_urb() and prepare_silent_urb() can write
iso_frame_desc[] past the allocation; their existing bounds limit payload
bytes, not the descriptor index.

The reproducer uses a high-speed UAC2 device declaring bInterval 1 for
implicit feedback capture (8 packets) and bInterval 4 for playback
(1 packet). On the first capture completion after the stream starts, it
accesses seven descriptors spanning 112 bytes beyond the one-packet URB:

  BUG: KASAN: slab-out-of-bounds in prepare_playback_urb (sound/usb/pcm.c:1560)
  Write of size 4 at addr ffff88801e696ad0 by task vhci_rx/178
   prepare_playback_urb (sound/usb/pcm.c:1560)
   prepare_outbound_urb (sound/usb/endpoint.c:340)
   snd_usb_queue_pending_output_urbs (sound/usb/endpoint.c:501)
   snd_complete_urb (sound/usb/endpoint.c:1834)
   __usb_hcd_giveback_urb (drivers/usb/core/hcd.c:1657)
   usb_hcd_giveback_urb (drivers/usb/core/hcd.c:1741)
   vhci_rx_loop (drivers/usb/usbip/vhci_rx.c:107)
   kthread (kernel/kthread.c:436)
  The buggy address belongs to the object at ffff88801e696a00
   which belongs to the cache kmalloc-256 of size 256
  The buggy address is located 0 bytes to the right of
   allocated 208-byte region [ffff88801e696a00, ffff88801e696ad0)

Record the allocated packet count per endpoint and clamp both the adopted
count and the packet-size copy to it. Fold the Format Type II delimiter
into urb_packs before the allocation loop so the recorded limit matches
every URB.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 32a1f64f8ff6e2c5391f5964baec697bce25b83c
Version < ad279ba0dc1781229f5b52f58d38d56960400e06
Status affected
Version e949fd266cfa1dcca7caa3faa698578c4ffd26d6
Version < 79c55a7b5d71cf2a6bbd4bd7698e1b10b70f813a
Status affected
Version cf044e44190234a41a788de1cdbb6c21f4a52e1e
Version < ab77e3f453c5f2499c08d6e8e218501d25bab39e
Status affected
Version cf044e44190234a41a788de1cdbb6c21f4a52e1e
Version < 76a986c980bb502c7688d605ac7a67fd257a9a1b
Status affected
Version df75696e70c88b22ed1d8c9d515993a858c58fd0
Status affected
Version 3a74f6b46c01d9a816378cd83c327a59f61475ec
Status affected
Version c26bde6301f20d9aafbfb7c2459a88c6a6ec178f
Status affected
Version f6fbdf797e016fbf968dd54301026b182175985a
Status affected
Version 6.12.75
Version < 6.12.112
Status affected
Version 6.18.16
Version < 6.18.54
Status affected
Version 5.15.202
Version < 5.16
Status affected
Version 6.1.165
Version < 6.2
Status affected
Version 6.6.128
Version < 6.7
Status affected
Version 6.19.6
Version < 6.20
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 7.0
Status affected
Version 0
Version < 7.0
Status unaffected
Version <= 6.12.*
Version 6.12.112
Status unaffected
Version <= 6.18.*
Version 6.18.54
Status unaffected
Version <= 7.2.*
Version 7.2.8
Status unaffected
Version <= *
Version 7.3-rc4
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.18% 0.064
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/ad279ba0dc1781229f5b52f58d38d56960400e06
https://git.kernel.org/stable/c/79c55a7b5d71cf2a6bbd4bd7698e1b10b70f813a
https://git.kernel.org/stable/c/ab77e3f453c5f2499c08d6e8e218501d25bab39e
https://git.kernel.org/stable/c/76a986c980bb502c7688d605ac7a67fd257a9a1b