๐Ÿ” CVE Alert

CVE-2026-74500

UNKNOWN 0.0

ALSA: usb-audio: fix stack info leak in RME Digiface status

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: fix stack info leak in RME Digiface status snd_rme_digiface_read_status() reads a four-word status block from the device into an uninitialised on-stack __le32 buf[4] and, whenever the vendor control-IN transfer does not return a negative error, copies all four words into the caller's status[]. snd_usb_ctl_msg() copies the full requested size back into the caller's buffer regardless of how many bytes the data stage actually delivered: buf = kmemdup(data, size, GFP_KERNEL); err = usb_control_msg(dev, pipe, request, requesttype, value, index, buf, size, timeout); memcpy(data, buf, size); usb_control_msg() returns the transferred length on a short control-IN, which is a non-negative value, and writes only that many bytes. The remainder of the copy back is the kmemdup()ed image of the caller's buffer, so a device answering with a short data stage leaves the trailing words of buf[] holding leftover kernel stack. The only guard in the caller is err < 0, so those words are stored into status[]. They then reach user space: snd_rme_digiface_get_status_val() selects a 16-bit halfword of status[] per the control's reg/mask, and the eight Digiface status controls together expose the whole 16-byte frame to an unprivileged reader of /dev/snd/controlC*. Zero-initialise the buffer so a short read yields zeros instead of stack residue. This mirrors snd_rme_get_status1(), which already clears its output word before the same kind of vendor read. Discovered by XBOW, triaged by Baul Lee <[email protected]>

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Aug 15, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
611a96f6acf2e74fe28cb90908a9c183862348ce < b3a346d5c99dd73cf84711f2a43e42691990efd2 611a96f6acf2e74fe28cb90908a9c183862348ce < 7ba01e0d3539d9cf0aef3e82938f1648147744cc 611a96f6acf2e74fe28cb90908a9c183862348ce < 98dbfbb38e297c25c5b0af4a9018d71ac25e8554 611a96f6acf2e74fe28cb90908a9c183862348ce < 441aaad150c57edaf57ee482a79a3bf4c5b7e353 3089703ab71484a8b9a7641051181d11d60f870c 50f63f11a6ddaa0d34574df72b3fa6ee257c057d 6.10.14 < 6.11 6.11.3 < 6.12
Linux / Linux
6.12

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/b3a346d5c99dd73cf84711f2a43e42691990efd2 git.kernel.org: https://git.kernel.org/stable/c/7ba01e0d3539d9cf0aef3e82938f1648147744cc git.kernel.org: https://git.kernel.org/stable/c/98dbfbb38e297c25c5b0af4a9018d71ac25e8554 git.kernel.org: https://git.kernel.org/stable/c/441aaad150c57edaf57ee482a79a3bf4c5b7e353