PT-2026-98594 · Linux · Linux

CVE-2026-97930

·

Published

2026-09-25

·

Updated

2026-09-25

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
ALSA: usbusx2y: fix in04 last array size mismatch with in04 buf
The in04 last array in struct usx2ydev is declared as char[24], but in04 buf is allocated as sizeof(struct us428 ctls) which is 21 bytes. In i usx2y in04 int(), when ctl snapshot last == -2 (initialization path):
memcpy(usx2y->in04 last, usx2y->in04 buf, sizeof(usx2y->in04 last));
This copies 24 bytes from a 21-byte slab allocation, reading 3 bytes past the end of the source object.
Introduce a USX2Y IN04 SIZE constant defined as sizeof(struct us428 ctls) and use it consistently for the in04 last array, the in04 buf allocation, the URB transfer length, and the comparison loop, replacing the bare 24 and 21 literals throughout.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-97930

Affected Products

Linux