PT-2026-106594 · Linux · Linux
CVE-2026-98265
·
Publicado
2026-10-06
·
Atualizado
2026-10-06
Nenhuma
Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
ALSA: usb-audio: Clamp implicit feedback packet count to URB capacity
data ep set params() allocates each data URB for exactly u->packets
isochronous frames, so urb->iso frame desc[] has u->packets slots and
ctx->packets is the driver's only record of that limit. For an implicit
feedback sink, snd usb queue pending output urbs() overwrites it with the
sync source's packet count, which is calculated independently from the
capture endpoint's parameters. When that count is larger,
prepare playback urb() and prepare silent urb() can write
iso frame desc[] past the allocation; their existing bounds limit payload
bytes, not the descriptor index.
The reproducer uses a high-speed UAC2 device declaring bInterval 1 for
implicit feedback capture (8 packets) and bInterval 4 for playback
(1 packet). On the first capture completion after the stream starts, it
accesses seven descriptors spanning 112 bytes beyond the one-packet URB:
BUG: KASAN: slab-out-of-bounds in prepare playback urb (sound/usb/pcm.c:1560)
Write of size 4 at addr ffff88801e696ad0 by task vhci rx/178
prepare playback urb (sound/usb/pcm.c:1560)
prepare outbound urb (sound/usb/endpoint.c:340)
snd usb queue pending output urbs (sound/usb/endpoint.c:501)
snd complete urb (sound/usb/endpoint.c:1834)
usb hcd giveback urb (drivers/usb/core/hcd.c:1657)
usb hcd giveback urb (drivers/usb/core/hcd.c:1741)
vhci rx loop (drivers/usb/usbip/vhci rx.c:107)
kthread (kernel/kthread.c:436)
The buggy address belongs to the object at ffff88801e696a00
which belongs to the cache kmalloc-256 of size 256
The buggy address is located 0 bytes to the right of
allocated 208-byte region [ffff88801e696a00, ffff88801e696ad0)
Record the allocated packet count per endpoint and clamp both the adopted
count and the packet-size copy to it. Fold the Format Type II delimiter
into urb packs before the allocation loop so the recorded limit matches
every URB.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Linux