« Volver al listado

CVE-2026-74497

Estado: RecibidaAlta (8.4)—

In the Linux kernel, the following vulnerability has been resolved:

ALSA: usb-audio: Clamp frame size in implicit-feedback mode

snd_usb_handle_sync_urb() scales received sync packet sizes by the sender's stride and stores the result directly in out_packet->packet_size[i]. If a connected USB device sends an oversized sync packet, this frame count can exceed ep->maxframesize.

The un-clamped frame count then propagates to the playback endpoint queue, potentially driving packet transfers beyond the endpoint's hardware frame limits.

Cap the calculated frame count against ep->maxframesize in snd_usb_handle_sync_urb() to prevent oversized packets from entering the playback queue.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vulnerabilidad local sin interacción (AV:L, UI:N) en controlador USB del kernel Linux que permite escalada mediante corrupción de memoria; impacto: DoS por desbordamiento de buffer y potencial ejecución de código en contexto del kernel.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-74497",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.4,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.5
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "28acb12014fb0c3e1edfdab1b1e3e266cf651550",
              "lessThan": "2d39fea6d3c19a2f5811d123114d92e3d0115fd1",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "28acb12014fb0c3e1edfdab1b1e3e266cf651550",
              "lessThan": "09cf3dbbb4256a43feb91d2f51f274510a9ada47",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "28acb12014fb0c3e1edfdab1b1e3e266cf651550",
              "lessThan": "cfa8d3e0e8b812c4db4d5241f62b6bdbab2bd7be",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "28acb12014fb0c3e1edfdab1b1e3e266cf651550",
              "lessThan": "56ac3e7c90f6b45969c3fd07a98fad760ffd6901",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "28acb12014fb0c3e1edfdab1b1e3e266cf651550",
              "lessThan": "be97fea7451d758881b95af78e900dd0d58a382a",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "28acb12014fb0c3e1edfdab1b1e3e266cf651550",
              "lessThan": "2db4535d6af79276a64449201c5be5feffb31c64",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "28acb12014fb0c3e1edfdab1b1e3e266cf651550",
              "lessThan": "53f0aa37eb945f3c983f61d12fc35eb33debb8a9",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "28acb12014fb0c3e1edfdab1b1e3e266cf651550",
              "lessThan": "8d7a30c50c2e58a6839634ed0acde14466d1dc61",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "sound/usb/endpoint.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "3.8"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "3.8",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.265",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.216",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.183",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.151",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.103",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.44",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.1.8",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "sound/usb/endpoint.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-08-15T13:17:54.657",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/09cf3dbbb4256a43feb91d2f51f274510a9ada47",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/2d39fea6d3c19a2f5811d123114d92e3d0115fd1",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/2db4535d6af79276a64449201c5be5feffb31c64",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/53f0aa37eb945f3c983f61d12fc35eb33debb8a9",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/56ac3e7c90f6b45969c3fd07a98fad760ffd6901",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/8d7a30c50c2e58a6839634ed0acde14466d1dc61",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/be97fea7451d758881b95af78e900dd0d58a382a",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/cfa8d3e0e8b812c4db4d5241f62b6bdbab2bd7be",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: usb-audio: Clamp frame size in implicit-feedback mode\n\nsnd_usb_handle_sync_urb() scales received sync packet sizes by the sender's\nstride and stores the result directly in out_packet->packet_size[i]. If a\nconnected USB device sends an oversized sync packet, this frame count can\nexceed ep->maxframesize.\n\nThe un-clamped frame count then propagates to the playback endpoint queue,\npotentially driving packet transfers beyond the endpoint's hardware frame\nlimits.\n\nCap the calculated frame count against ep->maxframesize in\nsnd_usb_handle_sync_urb() to prevent oversized packets from entering the\nplayback queue."
    }
  ],
  "lastModified": "2026-08-19T17:21:06.910",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}