๐Ÿ” CVE Alert

CVE-2026-74497

HIGH 8.4

ALSA: usb-audio: Clamp frame size in implicit-feedback mode

CVSS Score
8.4
EPSS Score
0.1%
EPSS Percentile
4th

In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Clamp frame size in implicit-feedback mode snd_usb_handle_sync_urb() scales received sync packet sizes by the sender's stride and stores the result directly in out_packet->packet_size[i]. If a connected USB device sends an oversized sync packet, this frame count can exceed ep->maxframesize. The un-clamped frame count then propagates to the playback endpoint queue, potentially driving packet transfers beyond the endpoint's hardware frame limits. Cap the calculated frame count against ep->maxframesize in snd_usb_handle_sync_urb() to prevent oversized packets from entering the playback queue.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Aug 15, 2026
Last Updated Aug 19, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new high vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Linux / Linux
28acb12014fb0c3e1edfdab1b1e3e266cf651550 < 2d39fea6d3c19a2f5811d123114d92e3d0115fd1 28acb12014fb0c3e1edfdab1b1e3e266cf651550 < 09cf3dbbb4256a43feb91d2f51f274510a9ada47 28acb12014fb0c3e1edfdab1b1e3e266cf651550 < cfa8d3e0e8b812c4db4d5241f62b6bdbab2bd7be 28acb12014fb0c3e1edfdab1b1e3e266cf651550 < 56ac3e7c90f6b45969c3fd07a98fad760ffd6901 28acb12014fb0c3e1edfdab1b1e3e266cf651550 < be97fea7451d758881b95af78e900dd0d58a382a 28acb12014fb0c3e1edfdab1b1e3e266cf651550 < 2db4535d6af79276a64449201c5be5feffb31c64 28acb12014fb0c3e1edfdab1b1e3e266cf651550 < 53f0aa37eb945f3c983f61d12fc35eb33debb8a9 28acb12014fb0c3e1edfdab1b1e3e266cf651550 < 8d7a30c50c2e58a6839634ed0acde14466d1dc61
Linux / Linux
3.8

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/2d39fea6d3c19a2f5811d123114d92e3d0115fd1 git.kernel.org: https://git.kernel.org/stable/c/09cf3dbbb4256a43feb91d2f51f274510a9ada47 git.kernel.org: https://git.kernel.org/stable/c/cfa8d3e0e8b812c4db4d5241f62b6bdbab2bd7be git.kernel.org: https://git.kernel.org/stable/c/56ac3e7c90f6b45969c3fd07a98fad760ffd6901 git.kernel.org: https://git.kernel.org/stable/c/be97fea7451d758881b95af78e900dd0d58a382a git.kernel.org: https://git.kernel.org/stable/c/2db4535d6af79276a64449201c5be5feffb31c64 git.kernel.org: https://git.kernel.org/stable/c/53f0aa37eb945f3c983f61d12fc35eb33debb8a9 git.kernel.org: https://git.kernel.org/stable/c/8d7a30c50c2e58a6839634ed0acde14466d1dc61