« Volver al listado

CVE-2026-74502

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

ALSA: ump: fix double free of out_cvts on rawmidi error

snd_ump_attach_legacy_rawmidi() allocates the legacy conversion array ump->out_cvts and, on the snd_rawmidi_new() error path, frees it with kfree() but leaves ump->out_cvts pointing at the freed memory. When the endpoint is later torn down, snd_ump_endpoint_free() frees ump->out_cvts a second time, resulting in a double free.

The host snd-usb-audio driver attaches the legacy rawmidi for any USB MIDI 2.0 (UMP) device, so a device that makes snd_rawmidi_new() fail reaches this path on enumeration.

Leer descripción completaMostrar menos

Clear ump->out_cvts after freeing it on the error path so it is not freed again during teardown.

Discovered by XBOW, triaged by Baul Lee <baul.lee@xbow.com>

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-74502",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "33cd7630782df2230529c3e8f1a6d0ae9cd6ab49",
              "lessThan": "e84d2e53a05c78a04d1343eeb0f31a79456e79fc",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "33cd7630782df2230529c3e8f1a6d0ae9cd6ab49",
              "lessThan": "3302aaeac4f7ee6b775850db21d5f61064ce70ad",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "33cd7630782df2230529c3e8f1a6d0ae9cd6ab49",
              "lessThan": "032746c2dd9a4ea0774b04ac8a29e2ea628f106e",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "33cd7630782df2230529c3e8f1a6d0ae9cd6ab49",
              "lessThan": "c57001f55f97ef856fb6527e376c5c4a056a53a4",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "33cd7630782df2230529c3e8f1a6d0ae9cd6ab49",
              "lessThan": "70c977815af0d997feb2d0c5d284d55689bf7051",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "sound/core/ump.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.5"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.5",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.6.151",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.103",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.44",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.1.8",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "sound/core/ump.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-08-15T13:17:55.197",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/032746c2dd9a4ea0774b04ac8a29e2ea628f106e",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/3302aaeac4f7ee6b775850db21d5f61064ce70ad",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/70c977815af0d997feb2d0c5d284d55689bf7051",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/c57001f55f97ef856fb6527e376c5c4a056a53a4",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/e84d2e53a05c78a04d1343eeb0f31a79456e79fc",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: ump: fix double free of out_cvts on rawmidi error\n\nsnd_ump_attach_legacy_rawmidi() allocates the legacy conversion array\nump->out_cvts and, on the snd_rawmidi_new() error path, frees it with\nkfree() but leaves ump->out_cvts pointing at the freed memory.  When the\nendpoint is later torn down, snd_ump_endpoint_free() frees ump->out_cvts\na second time, resulting in a double free.\n\nThe host snd-usb-audio driver attaches the legacy rawmidi for any USB\nMIDI 2.0 (UMP) device, so a device that makes snd_rawmidi_new() fail\nreaches this path on enumeration.\n\nClear ump->out_cvts after freeing it on the error path so it is not\nfreed again during teardown.\n\nDiscovered by XBOW, triaged by Baul Lee <baul.lee@xbow.com>"
    }
  ],
  "lastModified": "2026-08-17T06:19:46.693",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}