CVE-2026-98265 (GCVE-0-2026-98265)

Vulnerability from cvelistv5 – Published: 2026-10-06 08:45 – Updated: 2026-10-06 08:45
VLAI
Title
ALSA: usb-audio: Clamp implicit feedback packet count to URB capacity
Summary
In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Clamp implicit feedback packet count to URB capacity data_ep_set_params() allocates each data URB for exactly u->packets isochronous frames, so urb->iso_frame_desc[] has u->packets slots and ctx->packets is the driver's only record of that limit. For an implicit feedback sink, snd_usb_queue_pending_output_urbs() overwrites it with the sync source's packet count, which is calculated independently from the capture endpoint's parameters. When that count is larger, prepare_playback_urb() and prepare_silent_urb() can write iso_frame_desc[] past the allocation; their existing bounds limit payload bytes, not the descriptor index. The reproducer uses a high-speed UAC2 device declaring bInterval 1 for implicit feedback capture (8 packets) and bInterval 4 for playback (1 packet). On the first capture completion after the stream starts, it accesses seven descriptors spanning 112 bytes beyond the one-packet URB: BUG: KASAN: slab-out-of-bounds in prepare_playback_urb (sound/usb/pcm.c:1560) Write of size 4 at addr ffff88801e696ad0 by task vhci_rx/178 prepare_playback_urb (sound/usb/pcm.c:1560) prepare_outbound_urb (sound/usb/endpoint.c:340) snd_usb_queue_pending_output_urbs (sound/usb/endpoint.c:501) snd_complete_urb (sound/usb/endpoint.c:1834) __usb_hcd_giveback_urb (drivers/usb/core/hcd.c:1657) usb_hcd_giveback_urb (drivers/usb/core/hcd.c:1741) vhci_rx_loop (drivers/usb/usbip/vhci_rx.c:107) kthread (kernel/kthread.c:436) The buggy address belongs to the object at ffff88801e696a00 which belongs to the cache kmalloc-256 of size 256 The buggy address is located 0 bytes to the right of allocated 208-byte region [ffff88801e696a00, ffff88801e696ad0) Record the allocated packet count per endpoint and clamp both the adopted count and the packet-size copy to it. Fold the Format Type II delimiter into urb_packs before the allocation loop so the recorded limit matches every URB.
Severity
No CVSS data available.
Impacted products
Vendor Product Version
Linux Linux Affected: 32a1f64f8ff6e2c5391f5964baec697bce25b83c , < ad279ba0dc1781229f5b52f58d38d56960400e06 (git)
Affected: e949fd266cfa1dcca7caa3faa698578c4ffd26d6 , < 79c55a7b5d71cf2a6bbd4bd7698e1b10b70f813a (git)
Affected: cf044e44190234a41a788de1cdbb6c21f4a52e1e , < ab77e3f453c5f2499c08d6e8e218501d25bab39e (git)
Affected: cf044e44190234a41a788de1cdbb6c21f4a52e1e , < 76a986c980bb502c7688d605ac7a67fd257a9a1b (git)
Affected: df75696e70c88b22ed1d8c9d515993a858c58fd0 (git)
Affected: 3a74f6b46c01d9a816378cd83c327a59f61475ec (git)
Affected: c26bde6301f20d9aafbfb7c2459a88c6a6ec178f (git)
Affected: f6fbdf797e016fbf968dd54301026b182175985a (git)
Affected: 6.12.75 , < 6.12.112 (semver)
Affected: 6.18.16 , < 6.18.54 (semver)
Affected: 5.15.202 , < 5.16 (semver)
Affected: 6.1.165 , < 6.2 (semver)
Affected: 6.6.128 , < 6.7 (semver)
Affected: 6.19.6 , < 6.20 (semver)
Create a notification for this product.
Linux Linux Affected: 7.0
Unaffected: 0 , < 7.0 (semver)
Unaffected: 6.12.112 , ≤ 6.12.* (semver)
Unaffected: 6.18.54 , ≤ 6.18.* (semver)
Unaffected: 7.2.8 , ≤ 7.2.* (semver)
Unaffected: 7.3-rc4 , ≤ * (original_commit_for_fix)
Create a notification for this product.
Show details on NVD website

{
  "containers": {
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "sound/usb/card.h",
            "sound/usb/endpoint.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "ad279ba0dc1781229f5b52f58d38d56960400e06",
              "status": "affected",
              "version": "32a1f64f8ff6e2c5391f5964baec697bce25b83c",
              "versionType": "git"
            },
            {
              "lessThan": "79c55a7b5d71cf2a6bbd4bd7698e1b10b70f813a",
              "status": "affected",
              "version": "e949fd266cfa1dcca7caa3faa698578c4ffd26d6",
              "versionType": "git"
            },
            {
              "lessThan": "ab77e3f453c5f2499c08d6e8e218501d25bab39e",
              "status": "affected",
              "version": "cf044e44190234a41a788de1cdbb6c21f4a52e1e",
              "versionType": "git"
            },
            {
              "lessThan": "76a986c980bb502c7688d605ac7a67fd257a9a1b",
              "status": "affected",
              "version": "cf044e44190234a41a788de1cdbb6c21f4a52e1e",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "df75696e70c88b22ed1d8c9d515993a858c58fd0",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "3a74f6b46c01d9a816378cd83c327a59f61475ec",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "c26bde6301f20d9aafbfb7c2459a88c6a6ec178f",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "f6fbdf797e016fbf968dd54301026b182175985a",
              "versionType": "git"
            },
            {
              "lessThan": "6.12.112",
              "status": "affected",
              "version": "6.12.75",
              "versionType": "semver"
            },
            {
              "lessThan": "6.18.54",
              "status": "affected",
              "version": "6.18.16",
              "versionType": "semver"
            },
            {
              "lessThan": "5.16",
              "status": "affected",
              "version": "5.15.202",
              "versionType": "semver"
            },
            {
              "lessThan": "6.2",
              "status": "affected",
              "version": "6.1.165",
              "versionType": "semver"
            },
            {
              "lessThan": "6.7",
              "status": "affected",
              "version": "6.6.128",
              "versionType": "semver"
            },
            {
              "lessThan": "6.20",
              "status": "affected",
              "version": "6.19.6",
              "versionType": "semver"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "sound/usb/card.h",
            "sound/usb/endpoint.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "7.0"
            },
            {
              "lessThan": "7.0",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.12.*",
              "status": "unaffected",
              "version": "6.12.112",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.18.*",
              "status": "unaffected",
              "version": "6.18.54",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "7.2.*",
              "status": "unaffected",
              "version": "7.2.8",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "7.3-rc4",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.12.112",
                  "versionStartIncluding": "6.12.75",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.18.54",
                  "versionStartIncluding": "6.18.16",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.2.8",
                  "versionStartIncluding": "7.0",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.3-rc4",
                  "versionStartIncluding": "7.0",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionStartIncluding": "5.15.202",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionStartIncluding": "6.1.165",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionStartIncluding": "6.6.128",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionStartIncluding": "6.19.6",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: usb-audio: Clamp implicit feedback packet count to URB capacity\n\ndata_ep_set_params() allocates each data URB for exactly u-\u003epackets\nisochronous frames, so urb-\u003eiso_frame_desc[] has u-\u003epackets slots and\nctx-\u003epackets is the driver\u0027s only record of that limit. For an implicit\nfeedback sink, snd_usb_queue_pending_output_urbs() overwrites it with the\nsync source\u0027s packet count, which is calculated independently from the\ncapture endpoint\u0027s parameters. When that count is larger,\nprepare_playback_urb() and prepare_silent_urb() can write\niso_frame_desc[] past the allocation; their existing bounds limit payload\nbytes, not the descriptor index.\n\nThe reproducer uses a high-speed UAC2 device declaring bInterval 1 for\nimplicit feedback capture (8 packets) and bInterval 4 for playback\n(1 packet). On the first capture completion after the stream starts, it\naccesses seven descriptors spanning 112 bytes beyond the one-packet URB:\n\n  BUG: KASAN: slab-out-of-bounds in prepare_playback_urb (sound/usb/pcm.c:1560)\n  Write of size 4 at addr ffff88801e696ad0 by task vhci_rx/178\n   prepare_playback_urb (sound/usb/pcm.c:1560)\n   prepare_outbound_urb (sound/usb/endpoint.c:340)\n   snd_usb_queue_pending_output_urbs (sound/usb/endpoint.c:501)\n   snd_complete_urb (sound/usb/endpoint.c:1834)\n   __usb_hcd_giveback_urb (drivers/usb/core/hcd.c:1657)\n   usb_hcd_giveback_urb (drivers/usb/core/hcd.c:1741)\n   vhci_rx_loop (drivers/usb/usbip/vhci_rx.c:107)\n   kthread (kernel/kthread.c:436)\n  The buggy address belongs to the object at ffff88801e696a00\n   which belongs to the cache kmalloc-256 of size 256\n  The buggy address is located 0 bytes to the right of\n   allocated 208-byte region [ffff88801e696a00, ffff88801e696ad0)\n\nRecord the allocated packet count per endpoint and clamp both the adopted\ncount and the packet-size copy to it. Fold the Format Type II delimiter\ninto urb_packs before the allocation loop so the recorded limit matches\nevery URB."
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-10-06T08:45:28.438Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/ad279ba0dc1781229f5b52f58d38d56960400e06"
        },
        {
          "url": "https://git.kernel.org/stable/c/79c55a7b5d71cf2a6bbd4bd7698e1b10b70f813a"
        },
        {
          "url": "https://git.kernel.org/stable/c/ab77e3f453c5f2499c08d6e8e218501d25bab39e"
        },
        {
          "url": "https://git.kernel.org/stable/c/76a986c980bb502c7688d605ac7a67fd257a9a1b"
        }
      ],
      "title": "ALSA: usb-audio: Clamp implicit feedback packet count to URB capacity",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2026-98265",
    "datePublished": "2026-10-06T08:45:28.438Z",
    "dateReserved": "2026-09-25T10:25:14.333Z",
    "dateUpdated": "2026-10-06T08:45:28.438Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "vulnerability-lookup:meta": {
    "epss": {
      "cve": "CVE-2026-98265",
      "date": "2026-10-10",
      "epss": "0.00175",
      "percentile": "0.06454"
    },
    "nvd": {
      "cve": {
        "affected": [
          {
            "affectedData": [
              {
                "defaultStatus": "unaffected",
                "product": "Linux",
                "programFiles": [
                  "sound/usb/card.h",
                  "sound/usb/endpoint.c"
                ],
                "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                "vendor": "Linux",
                "versions": [
                  {
                    "lessThan": "ad279ba0dc1781229f5b52f58d38d56960400e06",
                    "status": "affected",
                    "version": "32a1f64f8ff6e2c5391f5964baec697bce25b83c",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "79c55a7b5d71cf2a6bbd4bd7698e1b10b70f813a",
                    "status": "affected",
                    "version": "e949fd266cfa1dcca7caa3faa698578c4ffd26d6",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "ab77e3f453c5f2499c08d6e8e218501d25bab39e",
                    "status": "affected",
                    "version": "cf044e44190234a41a788de1cdbb6c21f4a52e1e",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "76a986c980bb502c7688d605ac7a67fd257a9a1b",
                    "status": "affected",
                    "version": "cf044e44190234a41a788de1cdbb6c21f4a52e1e",
                    "versionType": "git"
                  },
                  {
                    "status": "affected",
                    "version": "df75696e70c88b22ed1d8c9d515993a858c58fd0",
                    "versionType": "git"
                  },
                  {
                    "status": "affected",
                    "version": "3a74f6b46c01d9a816378cd83c327a59f61475ec",
                    "versionType": "git"
                  },
                  {
                    "status": "affected",
                    "version": "c26bde6301f20d9aafbfb7c2459a88c6a6ec178f",
                    "versionType": "git"
                  },
                  {
                    "status": "affected",
                    "version": "f6fbdf797e016fbf968dd54301026b182175985a",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "6.12.112",
                    "status": "affected",
                    "version": "6.12.75",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "6.18.54",
                    "status": "affected",
                    "version": "6.18.16",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "5.16",
                    "status": "affected",
                    "version": "5.15.202",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "6.2",
                    "status": "affected",
                    "version": "6.1.165",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "6.7",
                    "status": "affected",
                    "version": "6.6.128",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "6.20",
                    "status": "affected",
                    "version": "6.19.6",
                    "versionType": "semver"
                  }
                ]
              },
              {
                "defaultStatus": "affected",
                "product": "Linux",
                "programFiles": [
                  "sound/usb/card.h",
                  "sound/usb/endpoint.c"
                ],
                "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                "vendor": "Linux",
                "versions": [
                  {
                    "status": "affected",
                    "version": "7.0"
                  },
                  {
                    "lessThan": "7.0",
                    "status": "unaffected",
                    "version": "0",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "6.12.*",
                    "status": "unaffected",
                    "version": "6.12.112",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "6.18.*",
                    "status": "unaffected",
                    "version": "6.18.54",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "7.2.*",
                    "status": "unaffected",
                    "version": "7.2.8",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "*",
                    "status": "unaffected",
                    "version": "7.3-rc4",
                    "versionType": "original_commit_for_fix"
                  }
                ]
              }
            ],
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
          }
        ],
        "cveTags": [],
        "descriptions": [
          {
            "lang": "en",
            "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: usb-audio: Clamp implicit feedback packet count to URB capacity\n\ndata_ep_set_params() allocates each data URB for exactly u-\u003epackets\nisochronous frames, so urb-\u003eiso_frame_desc[] has u-\u003epackets slots and\nctx-\u003epackets is the driver\u0027s only record of that limit. For an implicit\nfeedback sink, snd_usb_queue_pending_output_urbs() overwrites it with the\nsync source\u0027s packet count, which is calculated independently from the\ncapture endpoint\u0027s parameters. When that count is larger,\nprepare_playback_urb() and prepare_silent_urb() can write\niso_frame_desc[] past the allocation; their existing bounds limit payload\nbytes, not the descriptor index.\n\nThe reproducer uses a high-speed UAC2 device declaring bInterval 1 for\nimplicit feedback capture (8 packets) and bInterval 4 for playback\n(1 packet). On the first capture completion after the stream starts, it\naccesses seven descriptors spanning 112 bytes beyond the one-packet URB:\n\n  BUG: KASAN: slab-out-of-bounds in prepare_playback_urb (sound/usb/pcm.c:1560)\n  Write of size 4 at addr ffff88801e696ad0 by task vhci_rx/178\n   prepare_playback_urb (sound/usb/pcm.c:1560)\n   prepare_outbound_urb (sound/usb/endpoint.c:340)\n   snd_usb_queue_pending_output_urbs (sound/usb/endpoint.c:501)\n   snd_complete_urb (sound/usb/endpoint.c:1834)\n   __usb_hcd_giveback_urb (drivers/usb/core/hcd.c:1657)\n   usb_hcd_giveback_urb (drivers/usb/core/hcd.c:1741)\n   vhci_rx_loop (drivers/usb/usbip/vhci_rx.c:107)\n   kthread (kernel/kthread.c:436)\n  The buggy address belongs to the object at ffff88801e696a00\n   which belongs to the cache kmalloc-256 of size 256\n  The buggy address is located 0 bytes to the right of\n   allocated 208-byte region [ffff88801e696a00, ffff88801e696ad0)\n\nRecord the allocated packet count per endpoint and clamp both the adopted\ncount and the packet-size copy to it. Fold the Format Type II delimiter\ninto urb_packs before the allocation loop so the recorded limit matches\nevery URB."
          }
        ],
        "id": "CVE-2026-98265",
        "lastModified": "2026-10-06T09:18:15.797",
        "metrics": {},
        "published": "2026-10-06T09:18:15.797",
        "references": [
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/76a986c980bb502c7688d605ac7a67fd257a9a1b"
          },
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/79c55a7b5d71cf2a6bbd4bd7698e1b10b70f813a"
          },
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/ab77e3f453c5f2499c08d6e8e218501d25bab39e"
          },
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/ad279ba0dc1781229f5b52f58d38d56960400e06"
          }
        ],
        "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "vulnStatus": "Received"
      }
    },
    "suse_vex": {
      "aggregate_severity": "moderate",
      "current_release_date": "2026-10-07T23:45:31Z",
      "cve": "CVE-2026-98265",
      "id": "CVE-2026-98265",
      "initial_release_date": "2026-10-07T23:45:31Z",
      "product_status:known_affected": "49",
      "product_status:known_not_affected": "298",
      "source": "SUSE CSAF VEX",
      "status": "interim",
      "title": "SUSE CVE CVE-2026-98265",
      "url": "https://ftp.suse.com/pub/projects/security/csaf-vex/cve-2026-98265.json",
      "version": "2"
    }
  }
}



Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Forecast uses a logistic model when the trend is rising, or an exponential decay model when the trend is falling. Fitted via linearized least squares.

Sightings

Author Source Type Date Other

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or observed by the user.
  • Confirmed: The vulnerability has been validated from an analyst's perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
  • Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
  • Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
  • Not confirmed: The user expressed doubt about the validity of the vulnerability.
  • Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.

Loading…

Loading…

Loading…

Related by attack behaviour

Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.


Loading…