๐Ÿ” CVE Alert

CVE-2026-80829

UNKNOWN 0.0

ALSA: usb-audio: fix OOB write in snd_usbmidi_novation_output()

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: fix OOB write in snd_usbmidi_novation_output() snd_usbmidi_novation_output() lays out a two-byte header at transfer_buffer[0..1] and passes &transfer_buffer[2] together with a length of ep->max_transfer - 2 to snd_rawmidi_transmit(): count = snd_rawmidi_transmit(ep->ports[0].substream, &transfer_buffer[2], ep->max_transfer - 2); ep->max_transfer comes from the output endpoint's wMaxPacketSize via usb_maxpacket(). A malformed or malicious device can advertise a bulk OUT endpoint with a wMaxPacketSize of 1 - the USB core only clamps this value downwards - so ep->max_transfer becomes 1 and the count argument becomes -1. snd_rawmidi_transmit() passes the negative count on to __snd_rawmidi_transmit_peek(), where "if (count1 > count) count1 = count" leaves count1 negative; get_aligned_size() keeps it negative for a byte-stream substream, so the following memcpy(buffer, ..., count1) runs with a (size_t)-1 length and writes far past the transfer buffer, which was allocated with usb_alloc_coherent(ep->max_transfer). This is the same class of bug that was fixed for snd_usbmidi_akai_output() in commit 0970274613fb ("ALSA: usb-audio: fix OOB write in snd_usbmidi_akai_output()"); the novation output routine was left unguarded. Bail out when the endpoint cannot hold the two-byte header plus at least one payload byte.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 4, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 558fc4485ecc704edfe7876d6cebae4738ff7ef8 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 9c8212436631b0063cb021e9f58df438e3db84d0 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < e9c00d7533f99aa9833c4b598f47e3b3202fdb9a 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 94e4562fcc81badd1d467ddfb88c27e4fae974c2 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 7639ec9755d3ec0ec8cd7c0fdd2c3d3997434870 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 91919b3b99ab7ce3d7dbb39fcf7c6c742a663c0c 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 7f00dbddb51f4f74325cdc7c3f6b19fb3392481a 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 1074c2306901b44ebcb83855583c6776e1e392ea 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 1035a8f63bae28e498b0e7b5ac91d749844a7158
Linux / Linux
2.6.12

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/558fc4485ecc704edfe7876d6cebae4738ff7ef8 git.kernel.org: https://git.kernel.org/stable/c/9c8212436631b0063cb021e9f58df438e3db84d0 git.kernel.org: https://git.kernel.org/stable/c/e9c00d7533f99aa9833c4b598f47e3b3202fdb9a git.kernel.org: https://git.kernel.org/stable/c/94e4562fcc81badd1d467ddfb88c27e4fae974c2 git.kernel.org: https://git.kernel.org/stable/c/7639ec9755d3ec0ec8cd7c0fdd2c3d3997434870 git.kernel.org: https://git.kernel.org/stable/c/91919b3b99ab7ce3d7dbb39fcf7c6c742a663c0c git.kernel.org: https://git.kernel.org/stable/c/7f00dbddb51f4f74325cdc7c3f6b19fb3392481a git.kernel.org: https://git.kernel.org/stable/c/1074c2306901b44ebcb83855583c6776e1e392ea git.kernel.org: https://git.kernel.org/stable/c/1035a8f63bae28e498b0e7b5ac91d749844a7158