PT-2026-90100 · Linux · Linux

CVE-2026-80970

·

Published

2026-09-11

·

Updated

2026-09-11

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
ALSA: FCP: do not copy out an uninitialised init response
fcp ioctl init() allocates its response buffer with kmalloc() and copies the whole buffer back to userspace:
buf size = init.step0 resp size + init.step2 resp size;

void *resp  free(kfree) =
	kmalloc(buf size, GFP KERNEL);
...
if (copy to user(arg->resp, resp, buf size))
	return -EFAULT;
Nothing clears the buffer, and the only writer of its leading step0 resp size bytes is the step-0 control transfer:
err = snd usb ctl msg(dev, usb rcvctrlpipe(dev, 0),
	FCP USB REQ STEP0,
	USB RECIP INTERFACE | USB TYPE CLASS | USB DIR IN,
	0, private->bInterfaceNumber,
	step0 resp, private->step0 resp size);
if (err < 0)
	return err;
usb fill control urb() does not set URB SHORT NOT OK, so a short or zero-length data stage completes with status 0 and snd usb ctl msg() returns a small actual length. The only check is err < 0, so a short transfer is accepted as success.
snd usb ctl msg() copies the full size back unconditionally:
buf = kmemdup(data, size, GFP KERNEL);
...
memcpy(data, buf, size);
Bytes the device never wrote are therefore restored into resp unchanged and copied to userspace. step0 resp size and step2 resp size are each validated only to 1..255, so the caller also picks the slab cache, from kmalloc-8 up to kmalloc-512.
On 7.2.0-rc5 (arm64), device answering step 0 with a zero-length data stage, s0 = s2 = 255:

init on alloc off, no spray

step0 window [0,255): nonzero=94/255 000: 00 80 60 06 00 00 ff ff 18 00 00 00 57 01 ea 01 010: 08 78 22 13 00 00 ff ff a8 c4 5f 80 00 80 ff ff

same kernel, kmalloc-512 pre-seeded with an 8-byte tag

step0 window [0,255): nonzero=219/255 tagbytes=232

identical run, init on alloc=1

step0 window [0,255): nonzero=0/255 tagbytes=0

all three runs

step2 window [255,510): device words matched=62/62
a8 c4 5f 80 00 80 ff ff is the little-endian kernel text address ffff8000805fc4a8. The step-2 window is unaffected, so the disclosure is exactly the step-0 region.
Zero the buffer, and require the step-0 transfer to deliver the full step0 resp size bytes so a short data stage is reported as an error.
Discovered by XBOW, triaged by Baul Lee baul.lee@xbow.com
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-80970

Affected Products

Linux