CVE-2026-98312
In the Linux kernel, the following vulnerability has been resolved:
ALSA: 6fire: fix OOB write from device-reported iso length
usb6fire_pcm_in_urb_handler() sizes each outgoing isochronous packet as (actual_length - 4) / (in_n_analog << 2) * (out_n_analog << 2) + 4, where actual_length is the unsigned length the device reported for the matching IN packet. A packet completed with status 0 and actual_length < 4 wraps the subtraction to 0x7fffffec; a zero-length isochronous packet is legal on the bus, and the preceding loop rejects only non-zero status. The sum reaches memset() on out_urb->buffer, a 4832-byte object from kcalloc(PCM_MAX_PACKET_SIZE, PCM_N_PACKETS_PER_URB).
Leer descripción completaMostrar menos
Even without the wrap the result is out of bounds: at 88.2/96 kHz the 4-in/6-out scaling turns a full 420-byte IN packet into 628, so eight packets span 5024 bytes of that buffer. usb_submit_urb() rejects an over-long descriptor only after the memset() and the usb6fire_pcm_playback() copy of user PCM data have run.
Guard the subtraction as the sibling usb6fire_pcm_capture() already does, and limit the frame count to what fits in rt->out_packet_size, the OUT endpoint's wMaxPacketSize. This bounds total_length by the buffer size while keeping each packet length aligned to a whole output frame.
Detalles técnicos trazas, registros y código del informe original
BUG: KASAN: out-of-bounds in usb6fire_pcm_in_urb_handler (sound/usb/6fire/pcm.c:338) Write of size 18446744073709551456 at addr ffff88802a3d0000 by task vhci_rx/5018 Call Trace: dump_stack_lvl (lib/dump_stack.c:94 lib/dump_stack.c:120) print_report (mm/kasan/report.c:378 mm/kasan/report.c:482) kasan_report (mm/kasan/report.c:595) kasan_check_range (mm/kasan/generic.c:186 mm/kasan/generic.c:200) __asan_memset (mm/kasan/shadow.c:84) usb6fire_pcm_in_urb_handler (sound/usb/6fire/pcm.c:338) __usb_hcd_giveback_urb (drivers/usb/core/hcd.c:1657) usb_hcd_giveback_urb (drivers/usb/core/hcd.c:1741) vhci_rx_loop (drivers/usb/usbip/vhci_rx.c:107 drivers/usb/usbip/vhci_rx.c:242) kthread (kernel/kthread.c:436) ret_from_fork (arch/x86/kernel/process.c:158) ret_from_fork_asm (arch/x86/entry/entry_64.S:245) Allocated by task 10: __kmalloc_cache_noprof (mm/slub.c:5563) usb6fire_pcm_init (sound/usb/6fire/pcm.c:560 sound/usb/6fire/pcm.c:595) usb6fire_chip_probe (sound/usb/6fire/chip.c:133) usb_probe_interface (drivers/usb/core/driver.c:399) The buggy address belongs to the object at ffff88802a3d0000 which belongs to the cache kmalloc-8k of size 8192 The buggy address is located 0 bytes inside of 4832-byte region [ffff88802a3d0000, ffff88802a3d12e0) Kernel panic - not syncing: Fatal exception in interrupt
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.18%
- Percentil entre todas las CVEs puntuadas: 7
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/001ba7c1d9677225a5ecbc3e60d4865c08bb21d8
- https://git.kernel.org/stable/c/1589afe2d099d3e817873bc474676968d7080410
- https://git.kernel.org/stable/c/246de677552fe5dede293a1543b632e9853f31e4
- https://git.kernel.org/stable/c/61e665fb48e9eee44ec6d610514af383b1802cc1
- https://git.kernel.org/stable/c/cdc31537012bc7a58c95c6750db321b69dd802bb
- https://git.kernel.org/stable/c/ea11ade10583cc45af515d6b24510dbfa0184ca6
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-98312",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "c6d43ba816d1cf1d125bfbfc938f2a28a87facf9",
"lessThan": "61e665fb48e9eee44ec6d610514af383b1802cc1",
"versionType": "git"
},
{
"status": "affected",
"version": "c6d43ba816d1cf1d125bfbfc938f2a28a87facf9",
"lessThan": "246de677552fe5dede293a1543b632e9853f31e4",
"versionType": "git"
},
{
"status": "affected",
"version": "c6d43ba816d1cf1d125bfbfc938f2a28a87facf9",
"lessThan": "001ba7c1d9677225a5ecbc3e60d4865c08bb21d8",
"versionType": "git"
},
{
"status": "affected",
"version": "c6d43ba816d1cf1d125bfbfc938f2a28a87facf9",
"lessThan": "ea11ade10583cc45af515d6b24510dbfa0184ca6",
"versionType": "git"
},
{
"status": "affected",
"version": "c6d43ba816d1cf1d125bfbfc938f2a28a87facf9",
"lessThan": "cdc31537012bc7a58c95c6750db321b69dd802bb",
"versionType": "git"
},
{
"status": "affected",
"version": "c6d43ba816d1cf1d125bfbfc938f2a28a87facf9",
"lessThan": "1589afe2d099d3e817873bc474676968d7080410",
"versionType": "git"
}
],
"programFiles": [
"sound/usb/6fire/pcm.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.39"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "2.6.39",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.1.189",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.158",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.112",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.54",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.2.8",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc4",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"sound/usb/6fire/pcm.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-10-06T09:18:22.727",
"references": [
{
"url": "https://git.kernel.org/stable/c/001ba7c1d9677225a5ecbc3e60d4865c08bb21d8",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/1589afe2d099d3e817873bc474676968d7080410",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/246de677552fe5dede293a1543b632e9853f31e4",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/61e665fb48e9eee44ec6d610514af383b1802cc1",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/cdc31537012bc7a58c95c6750db321b69dd802bb",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/ea11ade10583cc45af515d6b24510dbfa0184ca6",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: 6fire: fix OOB write from device-reported iso length\n\nusb6fire_pcm_in_urb_handler() sizes each outgoing isochronous packet as\n(actual_length - 4) / (in_n_analog << 2) * (out_n_analog << 2) + 4, where\nactual_length is the unsigned length the device reported for the matching\nIN packet. A packet completed with status 0 and actual_length < 4 wraps\nthe subtraction to 0x7fffffec; a zero-length isochronous packet is legal\non the bus, and the preceding loop rejects only non-zero status. The sum\nreaches memset() on out_urb->buffer, a 4832-byte object from\nkcalloc(PCM_MAX_PACKET_SIZE, PCM_N_PACKETS_PER_URB).\n\nEven without the wrap the result is out of bounds: at 88.2/96 kHz the\n4-in/6-out scaling turns a full 420-byte IN packet into 628, so eight\npackets span 5024 bytes of that buffer. usb_submit_urb() rejects an\nover-long descriptor only after the memset() and the\nusb6fire_pcm_playback() copy of user PCM data have run.\n\nGuard the subtraction as the sibling usb6fire_pcm_capture() already does,\nand limit the frame count to what fits in rt->out_packet_size, the OUT\nendpoint's wMaxPacketSize. This bounds total_length by the buffer size\nwhile keeping each packet length aligned to a whole output frame.\n\n BUG: KASAN: out-of-bounds in usb6fire_pcm_in_urb_handler (sound/usb/6fire/pcm.c:338)\n Write of size 18446744073709551456 at addr ffff88802a3d0000 by task vhci_rx/5018\n Call Trace:\n dump_stack_lvl (lib/dump_stack.c:94 lib/dump_stack.c:120)\n print_report (mm/kasan/report.c:378 mm/kasan/report.c:482)\n kasan_report (mm/kasan/report.c:595)\n kasan_check_range (mm/kasan/generic.c:186 mm/kasan/generic.c:200)\n __asan_memset (mm/kasan/shadow.c:84)\n usb6fire_pcm_in_urb_handler (sound/usb/6fire/pcm.c:338)\n __usb_hcd_giveback_urb (drivers/usb/core/hcd.c:1657)\n usb_hcd_giveback_urb (drivers/usb/core/hcd.c:1741)\n vhci_rx_loop (drivers/usb/usbip/vhci_rx.c:107 drivers/usb/usbip/vhci_rx.c:242)\n kthread (kernel/kthread.c:436)\n ret_from_fork (arch/x86/kernel/process.c:158)\n ret_from_fork_asm (arch/x86/entry/entry_64.S:245)\n\n Allocated by task 10:\n __kmalloc_cache_noprof (mm/slub.c:5563)\n usb6fire_pcm_init (sound/usb/6fire/pcm.c:560 sound/usb/6fire/pcm.c:595)\n usb6fire_chip_probe (sound/usb/6fire/chip.c:133)\n usb_probe_interface (drivers/usb/core/driver.c:399)\n\n The buggy address belongs to the object at ffff88802a3d0000\n which belongs to the cache kmalloc-8k of size 8192\n The buggy address is located 0 bytes inside of\n 4832-byte region [ffff88802a3d0000, ffff88802a3d12e0)\n Kernel panic - not syncing: Fatal exception in interrupt"
}
],
"lastModified": "2026-10-06T09:18:22.727",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}