« Volver al listado

CVE-2026-80970

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

ALSA: FCP: do not copy out an uninitialised init response

fcp_ioctl_init() allocates its response buffer with kmalloc() and copies the whole buffer back to userspace:

Nothing clears the buffer, and the only writer of its leading step0_resp_size bytes is the step-0 control transfer:

usb_fill_control_urb() does not set URB_SHORT_NOT_OK, so a short or zero-length data stage completes with status 0 and snd_usb_ctl_msg() returns a small actual_length. The only check is err < 0, so a short transfer is accepted as success.

snd_usb_ctl_msg() copies the full size back unconditionally:

Leer descripción completaMostrar menos

Bytes the device never wrote are therefore restored into resp unchanged and copied to userspace. step0_resp_size and step2_resp_size are each validated only to 1..255, so the caller also picks the slab cache, from kmalloc-8 up to kmalloc-512.

On 7.2.0-rc5 (arm64), device answering step 0 with a zero-length data stage, s0 = s2 = 255:

a8 c4 5f 80 00 80 ff ff is the little-endian kernel text address ffff8000805fc4a8. The step-2 window is unaffected, so the disclosure is exactly the step-0 region.

Zero the buffer, and require the step-0 transfer to deliver the full step0_resp_size bytes so a short data stage is reported as an error.

Discovered by XBOW, triaged by Baul Lee <baul.lee@xbow.com>

Detalles técnicos trazas, registros y código del informe original
	buf_size = init.step0_resp_size + init.step2_resp_size;

	void *resp __free(kfree) =
		kmalloc(buf_size, GFP_KERNEL);
	...
	if (copy_to_user(arg->resp, resp, buf_size))
		return -EFAULT;

	err = snd_usb_ctl_msg(dev, usb_rcvctrlpipe(dev, 0),
		FCP_USB_REQ_STEP0,
		USB_RECIP_INTERFACE | USB_TYPE_CLASS | USB_DIR_IN,
		0, private->bInterfaceNumber,
		step0_resp, private->step0_resp_size);
	if (err < 0)
		return err;

	buf = kmemdup(data, size, GFP_KERNEL);
	...
	memcpy(data, buf, size);

  # init_on_alloc off, no spray
  step0 window [0,255): nonzero=94/255
  000: 00 80 60 06 00 00 ff ff 18 00 00 00 57 01 ea 01
  010: 08 78 22 13 00 00 ff ff a8 c4 5f 80 00 80 ff ff

  # same kernel, kmalloc-512 pre-seeded with an 8-byte tag
  step0 window [0,255): nonzero=219/255  tagbytes=232

  # identical run, init_on_alloc=1
  step0 window [0,255): nonzero=0/255  tagbytes=0

  # all three runs
  step2 window [255,510): device words matched=62/62

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-80970",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "46757a3e7d50dac923888e7fbe68377736f13c70",
              "lessThan": "e9e52437120fb5f802152877ba20c4b406c9fa9e",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "46757a3e7d50dac923888e7fbe68377736f13c70",
              "lessThan": "29ab2df278ab4f1d238cd9c1c393ee00db175cba",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "46757a3e7d50dac923888e7fbe68377736f13c70",
              "lessThan": "4335e387786479889e6db691fe06d345e52ea536",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "sound/usb/fcp.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.14"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.14",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.18.52",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.4",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "sound/usb/fcp.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-11T20:19:03.090",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/29ab2df278ab4f1d238cd9c1c393ee00db175cba",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/4335e387786479889e6db691fe06d345e52ea536",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/e9e52437120fb5f802152877ba20c4b406c9fa9e",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: FCP: do not copy out an uninitialised init response\n\nfcp_ioctl_init() allocates its response buffer with kmalloc() and copies\nthe whole buffer back to userspace:\n\n\tbuf_size = init.step0_resp_size + init.step2_resp_size;\n\n\tvoid *resp __free(kfree) =\n\t\tkmalloc(buf_size, GFP_KERNEL);\n\t...\n\tif (copy_to_user(arg->resp, resp, buf_size))\n\t\treturn -EFAULT;\n\nNothing clears the buffer, and the only writer of its leading\nstep0_resp_size bytes is the step-0 control transfer:\n\n\terr = snd_usb_ctl_msg(dev, usb_rcvctrlpipe(dev, 0),\n\t\tFCP_USB_REQ_STEP0,\n\t\tUSB_RECIP_INTERFACE | USB_TYPE_CLASS | USB_DIR_IN,\n\t\t0, private->bInterfaceNumber,\n\t\tstep0_resp, private->step0_resp_size);\n\tif (err < 0)\n\t\treturn err;\n\nusb_fill_control_urb() does not set URB_SHORT_NOT_OK, so a short or\nzero-length data stage completes with status 0 and snd_usb_ctl_msg()\nreturns a small actual_length.  The only check is err < 0, so a short\ntransfer is accepted as success.\n\nsnd_usb_ctl_msg() copies the full size back unconditionally:\n\n\tbuf = kmemdup(data, size, GFP_KERNEL);\n\t...\n\tmemcpy(data, buf, size);\n\nBytes the device never wrote are therefore restored into resp unchanged\nand copied to userspace.  step0_resp_size and step2_resp_size are each\nvalidated only to 1..255, so the caller also picks the slab cache, from\nkmalloc-8 up to kmalloc-512.\n\nOn 7.2.0-rc5 (arm64), device answering step 0 with a zero-length data\nstage, s0 = s2 = 255:\n\n  # init_on_alloc off, no spray\n  step0 window [0,255): nonzero=94/255\n  000: 00 80 60 06 00 00 ff ff 18 00 00 00 57 01 ea 01\n  010: 08 78 22 13 00 00 ff ff a8 c4 5f 80 00 80 ff ff\n\n  # same kernel, kmalloc-512 pre-seeded with an 8-byte tag\n  step0 window [0,255): nonzero=219/255  tagbytes=232\n\n  # identical run, init_on_alloc=1\n  step0 window [0,255): nonzero=0/255  tagbytes=0\n\n  # all three runs\n  step2 window [255,510): device words matched=62/62\n\na8 c4 5f 80 00 80 ff ff is the little-endian kernel text address\nffff8000805fc4a8.  The step-2 window is unaffected, so the disclosure is\nexactly the step-0 region.\n\nZero the buffer, and require the step-0 transfer to deliver the full\nstep0_resp_size bytes so a short data stage is reported as an error.\n\nDiscovered by XBOW, triaged by Baul Lee <baul.lee@xbow.com>"
    }
  ],
  "lastModified": "2026-09-14T13:18:51.770",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}