CVE-2026-74500
In the Linux kernel, the following vulnerability has been resolved:
ALSA: usb-audio: fix stack info leak in RME Digiface status
snd_rme_digiface_read_status() reads a four-word status block from the device into an uninitialised on-stack __le32 buf[4] and, whenever the vendor control-IN transfer does not return a negative error, copies all four words into the caller's status[].
snd_usb_ctl_msg() copies the full requested size back into the caller's buffer regardless of how many bytes the data stage actually delivered:
usb_control_msg() returns the transferred length on a short control-IN, which is a non-negative value, and writes only that many bytes.
Leer descripción completaMostrar menos
The remainder of the copy back is the kmemdup()ed image of the caller's buffer, so a device answering with a short data stage leaves the trailing words of buf[] holding leftover kernel stack. The only guard in the caller is err < 0, so those words are stored into status[].
They then reach user space: snd_rme_digiface_get_status_val() selects a 16-bit halfword of status[] per the control's reg/mask, and the eight Digiface status controls together expose the whole 16-byte frame to an unprivileged reader of /dev/snd/controlC*.
Zero-initialise the buffer so a short read yields zeros instead of stack residue. This mirrors snd_rme_get_status1(), which already clears its output word before the same kind of vendor read.
Discovered by XBOW, triaged by Baul Lee <baul.lee@xbow.com>
Detalles técnicos trazas, registros y código del informe original
buf = kmemdup(data, size, GFP_KERNEL); err = usb_control_msg(dev, pipe, request, requesttype, value, index, buf, size, timeout); memcpy(data, buf, size);
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.21%
- Percentil entre todas las CVEs puntuadas: 10
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-74500",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "611a96f6acf2e74fe28cb90908a9c183862348ce",
"lessThan": "b3a346d5c99dd73cf84711f2a43e42691990efd2",
"versionType": "git"
},
{
"status": "affected",
"version": "611a96f6acf2e74fe28cb90908a9c183862348ce",
"lessThan": "7ba01e0d3539d9cf0aef3e82938f1648147744cc",
"versionType": "git"
},
{
"status": "affected",
"version": "611a96f6acf2e74fe28cb90908a9c183862348ce",
"lessThan": "98dbfbb38e297c25c5b0af4a9018d71ac25e8554",
"versionType": "git"
},
{
"status": "affected",
"version": "611a96f6acf2e74fe28cb90908a9c183862348ce",
"lessThan": "441aaad150c57edaf57ee482a79a3bf4c5b7e353",
"versionType": "git"
},
{
"status": "affected",
"version": "3089703ab71484a8b9a7641051181d11d60f870c",
"versionType": "git"
},
{
"status": "affected",
"version": "50f63f11a6ddaa0d34574df72b3fa6ee257c057d",
"versionType": "git"
},
{
"status": "affected",
"version": "6.10.14",
"lessThan": "6.11",
"versionType": "semver"
},
{
"status": "affected",
"version": "6.11.3",
"lessThan": "6.12",
"versionType": "semver"
}
],
"programFiles": [
"sound/usb/mixer_quirks.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "6.12"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "6.12",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.12.103",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.44",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver",
"lessThanOrEqual": "7.1.*"
},
{
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"sound/usb/mixer_quirks.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-08-15T13:17:54.970",
"references": [
{
"url": "https://git.kernel.org/stable/c/441aaad150c57edaf57ee482a79a3bf4c5b7e353",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/7ba01e0d3539d9cf0aef3e82938f1648147744cc",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/98dbfbb38e297c25c5b0af4a9018d71ac25e8554",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/b3a346d5c99dd73cf84711f2a43e42691990efd2",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: usb-audio: fix stack info leak in RME Digiface status\n\nsnd_rme_digiface_read_status() reads a four-word status block from the\ndevice into an uninitialised on-stack __le32 buf[4] and, whenever the\nvendor control-IN transfer does not return a negative error, copies all\nfour words into the caller's status[].\n\nsnd_usb_ctl_msg() copies the full requested size back into the caller's\nbuffer regardless of how many bytes the data stage actually delivered:\n\n\tbuf = kmemdup(data, size, GFP_KERNEL);\n\terr = usb_control_msg(dev, pipe, request, requesttype,\n\t\t\t value, index, buf, size, timeout);\n\tmemcpy(data, buf, size);\n\nusb_control_msg() returns the transferred length on a short control-IN,\nwhich is a non-negative value, and writes only that many bytes. The\nremainder of the copy back is the kmemdup()ed image of the caller's\nbuffer, so a device answering with a short data stage leaves the\ntrailing words of buf[] holding leftover kernel stack. The only guard\nin the caller is err < 0, so those words are stored into status[].\n\nThey then reach user space: snd_rme_digiface_get_status_val() selects a\n16-bit halfword of status[] per the control's reg/mask, and the eight\nDigiface status controls together expose the whole 16-byte frame to an\nunprivileged reader of /dev/snd/controlC*.\n\nZero-initialise the buffer so a short read yields zeros instead of stack\nresidue. This mirrors snd_rme_get_status1(), which already clears its\noutput word before the same kind of vendor read.\n\nDiscovered by XBOW, triaged by Baul Lee <baul.lee@xbow.com>"
}
],
"lastModified": "2026-08-17T06:19:46.447",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}