« Volver al listado

CVE-2026-98265

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

ALSA: usb-audio: Clamp implicit feedback packet count to URB capacity

data_ep_set_params() allocates each data URB for exactly u->packets isochronous frames, so urb->iso_frame_desc[] has u->packets slots and ctx->packets is the driver's only record of that limit. For an implicit feedback sink, snd_usb_queue_pending_output_urbs() overwrites it with the sync source's packet count, which is calculated independently from the capture endpoint's parameters. When that count is larger, prepare_playback_urb() and prepare_silent_urb() can write iso_frame_desc[] past the allocation; their existing bounds limit payload bytes, not the descriptor index.

Leer descripción completaMostrar menos

The reproducer uses a high-speed UAC2 device declaring bInterval 1 for implicit feedback capture (8 packets) and bInterval 4 for playback (1 packet). On the first capture completion after the stream starts, it accesses seven descriptors spanning 112 bytes beyond the one-packet URB:

Record the allocated packet count per endpoint and clamp both the adopted count and the packet-size copy to it. Fold the Format Type II delimiter into urb_packs before the allocation loop so the recorded limit matches every URB.

Detalles técnicos trazas, registros y código del informe original
  BUG: KASAN: slab-out-of-bounds in prepare_playback_urb (sound/usb/pcm.c:1560)
  Write of size 4 at addr ffff88801e696ad0 by task vhci_rx/178
   prepare_playback_urb (sound/usb/pcm.c:1560)
   prepare_outbound_urb (sound/usb/endpoint.c:340)
   snd_usb_queue_pending_output_urbs (sound/usb/endpoint.c:501)
   snd_complete_urb (sound/usb/endpoint.c:1834)
   __usb_hcd_giveback_urb (drivers/usb/core/hcd.c:1657)
   usb_hcd_giveback_urb (drivers/usb/core/hcd.c:1741)
   vhci_rx_loop (drivers/usb/usbip/vhci_rx.c:107)
   kthread (kernel/kthread.c:436)
  The buggy address belongs to the object at ffff88801e696a00
   which belongs to the cache kmalloc-256 of size 256
  The buggy address is located 0 bytes to the right of
   allocated 208-byte region [ffff88801e696a00, ffff88801e696ad0)

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-98265",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "32a1f64f8ff6e2c5391f5964baec697bce25b83c",
              "lessThan": "ad279ba0dc1781229f5b52f58d38d56960400e06",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "e949fd266cfa1dcca7caa3faa698578c4ffd26d6",
              "lessThan": "79c55a7b5d71cf2a6bbd4bd7698e1b10b70f813a",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "cf044e44190234a41a788de1cdbb6c21f4a52e1e",
              "lessThan": "ab77e3f453c5f2499c08d6e8e218501d25bab39e",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "cf044e44190234a41a788de1cdbb6c21f4a52e1e",
              "lessThan": "76a986c980bb502c7688d605ac7a67fd257a9a1b",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "df75696e70c88b22ed1d8c9d515993a858c58fd0",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "3a74f6b46c01d9a816378cd83c327a59f61475ec",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "c26bde6301f20d9aafbfb7c2459a88c6a6ec178f",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "f6fbdf797e016fbf968dd54301026b182175985a",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "6.12.75",
              "lessThan": "6.12.112",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.18.16",
              "lessThan": "6.18.54",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "5.15.202",
              "lessThan": "5.16",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.1.165",
              "lessThan": "6.2",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.6.128",
              "lessThan": "6.7",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.19.6",
              "lessThan": "6.20",
              "versionType": "semver"
            }
          ],
          "programFiles": [
            "sound/usb/card.h",
            "sound/usb/endpoint.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "7.0"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "7.0",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.12.112",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.54",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.8",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc4",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "sound/usb/card.h",
            "sound/usb/endpoint.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-10-06T09:18:15.797",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/76a986c980bb502c7688d605ac7a67fd257a9a1b",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/79c55a7b5d71cf2a6bbd4bd7698e1b10b70f813a",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/ab77e3f453c5f2499c08d6e8e218501d25bab39e",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/ad279ba0dc1781229f5b52f58d38d56960400e06",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: usb-audio: Clamp implicit feedback packet count to URB capacity\n\ndata_ep_set_params() allocates each data URB for exactly u->packets\nisochronous frames, so urb->iso_frame_desc[] has u->packets slots and\nctx->packets is the driver's only record of that limit. For an implicit\nfeedback sink, snd_usb_queue_pending_output_urbs() overwrites it with the\nsync source's packet count, which is calculated independently from the\ncapture endpoint's parameters. When that count is larger,\nprepare_playback_urb() and prepare_silent_urb() can write\niso_frame_desc[] past the allocation; their existing bounds limit payload\nbytes, not the descriptor index.\n\nThe reproducer uses a high-speed UAC2 device declaring bInterval 1 for\nimplicit feedback capture (8 packets) and bInterval 4 for playback\n(1 packet). On the first capture completion after the stream starts, it\naccesses seven descriptors spanning 112 bytes beyond the one-packet URB:\n\n  BUG: KASAN: slab-out-of-bounds in prepare_playback_urb (sound/usb/pcm.c:1560)\n  Write of size 4 at addr ffff88801e696ad0 by task vhci_rx/178\n   prepare_playback_urb (sound/usb/pcm.c:1560)\n   prepare_outbound_urb (sound/usb/endpoint.c:340)\n   snd_usb_queue_pending_output_urbs (sound/usb/endpoint.c:501)\n   snd_complete_urb (sound/usb/endpoint.c:1834)\n   __usb_hcd_giveback_urb (drivers/usb/core/hcd.c:1657)\n   usb_hcd_giveback_urb (drivers/usb/core/hcd.c:1741)\n   vhci_rx_loop (drivers/usb/usbip/vhci_rx.c:107)\n   kthread (kernel/kthread.c:436)\n  The buggy address belongs to the object at ffff88801e696a00\n   which belongs to the cache kmalloc-256 of size 256\n  The buggy address is located 0 bytes to the right of\n   allocated 208-byte region [ffff88801e696a00, ffff88801e696ad0)\n\nRecord the allocated packet count per endpoint and clamp both the adopted\ncount and the packet-size copy to it. Fold the Format Type II delimiter\ninto urb_packs before the allocation loop so the recorded limit matches\nevery URB."
    }
  ],
  "lastModified": "2026-10-06T09:18:15.797",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}