PT-2026-37619 · Linux+3 · Linux Kernel+3

CVE-2026-43279

·

Published

2026-02-16

·

Updated

2026-08-23

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the ALSA usb-audio component where the system blindly assumes received packets fit the buffer size when silencing playback URB (USB Request Block) packets in implicit fb mode. If the capture stream setup differs from the playback stream, such as due to USB core max packet size limitations, it can lead to out-of-bounds (OOB) writes to the buffer, resulting in a kernel crash.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:27353
ALSA-2026:27354
ALSA-2026:27789
ALSA-2026:33685
BDU:2026-11735
CVE-2026-43279
OPENSUSE-SU-2026:21555-1
RHSA-2026:27353
RHSA-2026:27354
RHSA-2026:27789
RHSA-2026:33685
RHSA-2026:33900
RHSA-2026:34095
RHSA-2026:35863
RHSA-2026:35894
RHSA-2026:44522
RHSA-2026:46461
SUSE-SU-2026:23066-1
SUSE-SU-2026:23068-1
SUSE-SU-2026:23193-1
SUSE-SU-2026:23194-1
SUSE-SU-2026:23221-1
SUSE-SU-2026:23231-1
SUSE-SU-2026:23237-1
SUSE-SU-2026:23241-1
SUSE-SU-2026:23244-1
SUSE-SU-2026:2914-1
SUSE-SU-2026:3130-1
SUSE-SU-2026:3166-1
USN-8492-1
USN-8492-2
USN-8492-3
USN-8492-4
USN-8492-5
USN-8497-1
USN-8498-1
USN-8499-1
USN-8575-1
USN-8575-2
USN-8575-3
USN-8576-1
USN-8576-2
USN-8597-1
USN-8606-1
USN-8607-1
USN-8609-1
USN-8610-1
USN-8619-1
USN-8620-1
USN-8620-2
USN-8620-3
USN-8620-4
USN-8668-1

Affected Products

Linuxmint
Linux Kernel
Rocky Linux
Ubuntu