PT-2026-93674 · Linux · Linux Kernel

CVE-2026-90033

·

Published

2026-09-16

·

Updated

2026-09-24

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An out-of-bounds write exists in the snd usbmidi us122l output() function. The issue occurs when the function selects a count of 2 for devices slower than high speed without verifying it against ep->max transfer. If a device declares a one-byte bulk endpoint, the system takes two bytes from snd rawmidi transmit(), causing the memset operation used for padding to compute a negative value (1 - 2), which wraps to SIZE MAX and leads to an out-of-bounds write in the URB buffer.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-101543
CVE-2026-90033
OPENSUSE-SU-2026:11880-1

Affected Products

Linux Kernel