๐Ÿ” CVE Alert

CVE-2026-72403

UNKNOWN 0.0

ALSA: FCP: Fix NULL pointer dereference in interface lookup

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: ALSA: FCP: Fix NULL pointer dereference in interface lookup A malformed USB device can provide a vendor-specific interface without any endpoint descriptors. fcp_find_fc_interface() currently selects the first vendor-specific interface and reads endpoint 0 from it, without checking whether the interface actually has any endpoints. When bNumEndpoints is zero, no endpoint array is allocated for the parsed alternate setting, so get_endpoint(..., 0) yields an invalid endpoint descriptor pointer. Dereferencing it through usb_endpoint_num() then triggers a NULL pointer dereference. Skip vendor-specific interfaces that do not have any endpoints.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Aug 15, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
46757a3e7d50dac923888e7fbe68377736f13c70 < f28d7b5f1578a7501ab17b10643ed1e4f729187e 46757a3e7d50dac923888e7fbe68377736f13c70 < 3ab06151ffcb8c3aeb8f78508658b6c0f05be932 46757a3e7d50dac923888e7fbe68377736f13c70 < e1e31e0ec8a609e17fd2e86b77bc00d9cbb24d7c
Linux / Linux
6.14

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/f28d7b5f1578a7501ab17b10643ed1e4f729187e git.kernel.org: https://git.kernel.org/stable/c/3ab06151ffcb8c3aeb8f78508658b6c0f05be932 git.kernel.org: https://git.kernel.org/stable/c/e1e31e0ec8a609e17fd2e86b77bc00d9cbb24d7c