๐Ÿ” CVE Alert

CVE-2026-23318

UNKNOWN 0.0

ALSA: usb-audio: Use correct version for UAC3 header validation

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Use correct version for UAC3 header validation The entry of the validators table for UAC3 AC header descriptor is defined with the wrong protocol version UAC_VERSION_2, while it should have been UAC_VERSION_3. This results in the validator never matching for actual UAC3 devices (protocol == UAC_VERSION_3), causing their header descriptors to bypass validation entirely. A malicious USB device presenting a truncated UAC3 header could exploit this to cause out-of-bounds reads when the driver later accesses unvalidated descriptor fields. The bug was introduced in the same commit as the recently fixed UAC3 feature unit sub-type typo, and appears to be from the same copy-paste error when the UAC3 section was created from the UAC2 section.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Mar 25, 2026
Last Updated Apr 13, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
57f8770620e9b51c61089751f0b5ad3dbe376ff2 < 0dcd1ed96c03459cf14706885c9dd3c1fd8bd29f 57f8770620e9b51c61089751f0b5ad3dbe376ff2 < a0c6ae2ea84528f198bf7fd0117f12fd0cf6d7cc 57f8770620e9b51c61089751f0b5ad3dbe376ff2 < d3904ca40515272681ae61ad6f561c24f190957f 57f8770620e9b51c61089751f0b5ad3dbe376ff2 < 1e5753ff4c2e86aa88516f97a224c90a3d0b133e 57f8770620e9b51c61089751f0b5ad3dbe376ff2 < 499ffd15b00dc91ac95c28f76959dfb5cdcc84d5 57f8770620e9b51c61089751f0b5ad3dbe376ff2 < 54f9d645a5453d0bfece0c465d34aaf072ea99fa 17821e2fb16752f5d363fb5c3f8aab4df41b9bcc bf74a46aebb1b5ab5e5f25bafa4ae0a453ba813a
Linux / Linux
5.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/0dcd1ed96c03459cf14706885c9dd3c1fd8bd29f git.kernel.org: https://git.kernel.org/stable/c/a0c6ae2ea84528f198bf7fd0117f12fd0cf6d7cc git.kernel.org: https://git.kernel.org/stable/c/d3904ca40515272681ae61ad6f561c24f190957f git.kernel.org: https://git.kernel.org/stable/c/1e5753ff4c2e86aa88516f97a224c90a3d0b133e git.kernel.org: https://git.kernel.org/stable/c/499ffd15b00dc91ac95c28f76959dfb5cdcc84d5 git.kernel.org: https://git.kernel.org/stable/c/54f9d645a5453d0bfece0c465d34aaf072ea99fa