« Volver al listado

CVE-2026-74500

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

ALSA: usb-audio: fix stack info leak in RME Digiface status

snd_rme_digiface_read_status() reads a four-word status block from the device into an uninitialised on-stack __le32 buf[4] and, whenever the vendor control-IN transfer does not return a negative error, copies all four words into the caller's status[].

snd_usb_ctl_msg() copies the full requested size back into the caller's buffer regardless of how many bytes the data stage actually delivered:

usb_control_msg() returns the transferred length on a short control-IN, which is a non-negative value, and writes only that many bytes.

Leer descripción completaMostrar menos

The remainder of the copy back is the kmemdup()ed image of the caller's buffer, so a device answering with a short data stage leaves the trailing words of buf[] holding leftover kernel stack. The only guard in the caller is err < 0, so those words are stored into status[].

They then reach user space: snd_rme_digiface_get_status_val() selects a 16-bit halfword of status[] per the control's reg/mask, and the eight Digiface status controls together expose the whole 16-byte frame to an unprivileged reader of /dev/snd/controlC*.

Zero-initialise the buffer so a short read yields zeros instead of stack residue. This mirrors snd_rme_get_status1(), which already clears its output word before the same kind of vendor read.

Discovered by XBOW, triaged by Baul Lee <baul.lee@xbow.com>

Detalles técnicos trazas, registros y código del informe original
	buf = kmemdup(data, size, GFP_KERNEL);
	err = usb_control_msg(dev, pipe, request, requesttype,
			      value, index, buf, size, timeout);
	memcpy(data, buf, size);

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-74500",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "611a96f6acf2e74fe28cb90908a9c183862348ce",
              "lessThan": "b3a346d5c99dd73cf84711f2a43e42691990efd2",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "611a96f6acf2e74fe28cb90908a9c183862348ce",
              "lessThan": "7ba01e0d3539d9cf0aef3e82938f1648147744cc",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "611a96f6acf2e74fe28cb90908a9c183862348ce",
              "lessThan": "98dbfbb38e297c25c5b0af4a9018d71ac25e8554",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "611a96f6acf2e74fe28cb90908a9c183862348ce",
              "lessThan": "441aaad150c57edaf57ee482a79a3bf4c5b7e353",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "3089703ab71484a8b9a7641051181d11d60f870c",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "50f63f11a6ddaa0d34574df72b3fa6ee257c057d",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "6.10.14",
              "lessThan": "6.11",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.11.3",
              "lessThan": "6.12",
              "versionType": "semver"
            }
          ],
          "programFiles": [
            "sound/usb/mixer_quirks.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.12"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.12",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.12.103",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.44",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.1.8",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "sound/usb/mixer_quirks.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-08-15T13:17:54.970",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/441aaad150c57edaf57ee482a79a3bf4c5b7e353",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/7ba01e0d3539d9cf0aef3e82938f1648147744cc",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/98dbfbb38e297c25c5b0af4a9018d71ac25e8554",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/b3a346d5c99dd73cf84711f2a43e42691990efd2",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: usb-audio: fix stack info leak in RME Digiface status\n\nsnd_rme_digiface_read_status() reads a four-word status block from the\ndevice into an uninitialised on-stack __le32 buf[4] and, whenever the\nvendor control-IN transfer does not return a negative error, copies all\nfour words into the caller's status[].\n\nsnd_usb_ctl_msg() copies the full requested size back into the caller's\nbuffer regardless of how many bytes the data stage actually delivered:\n\n\tbuf = kmemdup(data, size, GFP_KERNEL);\n\terr = usb_control_msg(dev, pipe, request, requesttype,\n\t\t\t      value, index, buf, size, timeout);\n\tmemcpy(data, buf, size);\n\nusb_control_msg() returns the transferred length on a short control-IN,\nwhich is a non-negative value, and writes only that many bytes.  The\nremainder of the copy back is the kmemdup()ed image of the caller's\nbuffer, so a device answering with a short data stage leaves the\ntrailing words of buf[] holding leftover kernel stack.  The only guard\nin the caller is err < 0, so those words are stored into status[].\n\nThey then reach user space: snd_rme_digiface_get_status_val() selects a\n16-bit halfword of status[] per the control's reg/mask, and the eight\nDigiface status controls together expose the whole 16-byte frame to an\nunprivileged reader of /dev/snd/controlC*.\n\nZero-initialise the buffer so a short read yields zeros instead of stack\nresidue.  This mirrors snd_rme_get_status1(), which already clears its\noutput word before the same kind of vendor read.\n\nDiscovered by XBOW, triaged by Baul Lee <baul.lee@xbow.com>"
    }
  ],
  "lastModified": "2026-08-17T06:19:46.447",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}