CVE-2026-98265
Received Received - Intake

Buffer Overflow in Linux Kernel USB Audio Driver

Vulnerability report for CVE-2026-98265, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Clamp implicit feedback packet count to URB capacity data_ep_set_params() allocates each data URB for exactly u->packets isochronous frames, so urb->iso_frame_desc[] has u->packets slots and ctx->packets is the driver's only record of that limit. For an implicit feedback sink, snd_usb_queue_pending_output_urbs() overwrites it with the sync source's packet count, which is calculated independently from the capture endpoint's parameters. When that count is larger, prepare_playback_urb() and prepare_silent_urb() can write iso_frame_desc[] past the allocation; their existing bounds limit payload bytes, not the descriptor index. The reproducer uses a high-speed UAC2 device declaring bInterval 1 for implicit feedback capture (8 packets) and bInterval 4 for playback (1 packet). On the first capture completion after the stream starts, it accesses seven descriptors spanning 112 bytes beyond the one-packet URB: BUG: KASAN: slab-out-of-bounds in prepare_playback_urb (sound/usb/pcm.c:1560) Write of size 4 at addr ffff88801e696ad0 by task vhci_rx/178 prepare_playback_urb (sound/usb/pcm.c:1560) prepare_outbound_urb (sound/usb/endpoint.c:340) snd_usb_queue_pending_output_urbs (sound/usb/endpoint.c:501) snd_complete_urb (sound/usb/endpoint.c:1834) __usb_hcd_giveback_urb (drivers/usb/core/hcd.c:1657) usb_hcd_giveback_urb (drivers/usb/core/hcd.c:1741) vhci_rx_loop (drivers/usb/usbip/vhci_rx.c:107) kthread (kernel/kthread.c:436) The buggy address belongs to the object at ffff88801e696a00 which belongs to the cache kmalloc-256 of size 256 The buggy address is located 0 bytes to the right of allocated 208-byte region [ffff88801e696a00, ffff88801e696ad0) Record the allocated packet count per endpoint and clamp both the adopted count and the packet-size copy to it. Fold the Format Type II delimiter into urb_packs before the allocation loop so the recorded limit matches every URB.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 15 associated CPEs
Vendor Product Version / Range
Linux Linux 32a1f64f8ff6e2c5391f5964baec697bce25b83c
Linux Linux e949fd266cfa1dcca7caa3faa698578c4ffd26d6
Linux Linux cf044e44190234a41a788de1cdbb6c21f4a52e1e
Linux Linux cf044e44190234a41a788de1cdbb6c21f4a52e1e
Linux Linux df75696e70c88b22ed1d8c9d515993a858c58fd0
Linux Linux 3a74f6b46c01d9a816378cd83c327a59f61475ec
Linux Linux c26bde6301f20d9aafbfb7c2459a88c6a6ec178f
Linux Linux f6fbdf797e016fbf968dd54301026b182175985a
Linux Linux 6.12.75
Linux Linux 6.18.16
Linux Linux 5.15.202
Linux Linux 6.1.165
Linux Linux 6.6.128
Linux Linux 6.19.6
Linux Linux 7.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Linux kernel involves a buffer overflow in the ALSA USB audio driver. When using implicit feedback mode, the driver incorrectly uses the sync source's packet count instead of the capture endpoint's limit. This causes the driver to write beyond the allocated memory for USB data packets, leading to a slab-out-of-bounds write error.

Detection Guidance

This vulnerability is specific to the Linux kernel's ALSA USB audio driver and requires kernel memory corruption detection. Check kernel logs for slab-out-of-bounds errors or KASAN reports related to sound/usb/pcm.c or prepare_playback_urb. Monitor for USB audio device crashes or unexpected behavior during audio streaming.

Impact Analysis

This vulnerability could allow an attacker with physical access to a system to cause a kernel crash or execute arbitrary code with kernel privileges. It may lead to denial-of-service conditions or potential privilege escalation on affected systems using vulnerable USB audio devices.

Mitigation Strategies

Update your Linux kernel to the patched version that includes the fix for this vulnerability. If immediate updating is not possible, disable USB audio devices or restrict their use until the patch is applied. Monitor kernel security advisories for updates.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-98265. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart