CVE-2026-80971
Received Received - Intake

Use-After-Free in ALSA bcd2000 USB MIDI Driver

Vulnerability report for CVE-2026-80971, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-14

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: ALSA: bcd2000: clear the URB pointers on disconnect bcd2000_free_usb_related_resources() frees both URBs and leaves the pointers behind: usb_kill_urb(bcd2k->midi_out_urb); usb_kill_urb(bcd2k->midi_in_urb); usb_free_urb(bcd2k->midi_out_urb); usb_free_urb(bcd2k->midi_in_urb); The rawmidi device outlives that call. A substream that is still open when the device is unplugged reaches bcd2000_midi_send() from the trigger path on close. That function writes to the freed URB and then hands it to the USB core: bcd2k->midi_out_urb->transfer_buffer_length = BUFSIZE; ... ret = usb_submit_urb(bcd2k->midi_out_urb, GFP_ATOMIC); usb_kill_urb() does not stop a later submission either, so a submit that races the disconnect can requeue the URB after it has been reaped. midi_in_urb is exposed the same way: bcd2000_input_complete() resubmits it from the completion handler. KASAN on 7.2.0-rc5 (arm64): BUG: KASAN: slab-use-after-free in bcd2000_midi_send [snd_bcd2000] Write of size 4 at addr ffff00001827d388 by task bpoc/168 __asan_store4 bcd2000_midi_send [snd_bcd2000] bcd2000_midi_output_trigger [snd_bcd2000] snd_rawmidi_kernel_write1 close_substream.part.0 Freed by task 168: usb_free_urb bcd2000_disconnect [snd_bcd2000] BUG: KASAN: slab-use-after-free in usb_submit_urb Read of size 8 at addr ffff00001827d3b8 by task bpoc/168 Clear both pointers after freeing and test them on the paths that can still run. Poison the URBs before freeing them: usb_poison_urb() waits for a running completion handler and rejects any later submission, so after it returns the input path is quiesced and only the rawmidi trigger path can still reach bcd2000_midi_send(). No unpoison is needed; the URBs are freed on the next line. Discovered by XBOW, triaged by Baul Lee <baul.lee@xbow.com>

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-14
Generated
2026-10-02
AI Q&A
2026-09-12
EPSS Evaluated
2026-10-01
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Linux kernel involves a use-after-free issue in the ALSA bcd2000 driver. When the device is disconnected, URB pointers are freed but not cleared, allowing a still-open substream to later access these freed URBs. This can lead to memory corruption or crashes when the kernel tries to use the freed memory.

Detection Guidance

This vulnerability is specific to the Linux kernel's ALSA bcd2000 driver and requires kernel-level detection. Check kernel logs for slab-use-after-free errors related to snd_bcd2000 or usb_submit_urb. Use commands like dmesg | grep -i 'bcd2000\|use-after-free\|usb_submit_urb' to search for relevant errors.

Impact Analysis

If you use a system with the affected Linux kernel and the bcd2000 USB MIDI device, this vulnerability could cause system instability, crashes, or potential privilege escalation. Attackers might exploit it by unplugging the device while a MIDI substream is active, leading to memory corruption.

Compliance Impact

This vulnerability does not directly affect compliance with GDPR, HIPAA, or similar standards as it is a Linux kernel driver issue involving use-after-free in USB MIDI device handling. Compliance impacts would only occur if this flaw led to unauthorized data access or system instability in systems processing sensitive data, which is not described in the provided context.

Mitigation Strategies

Apply the kernel patch that clears URB pointers after freeing and uses usb_poison_urb() to quiesce the input path. Update to a Linux kernel version that includes the fix for CVE-2026-80971. If immediate patching is not possible, consider disabling the bcd2000 driver module (snd-bcd2000) if not in use.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-80971. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart