Impact
An out‑of‑bounds write occurs in the ALSA usb‑audio subsystem when a USB device advertises a Type II capture format. The kernel mis‑calculates the transfer buffer size by one packet, causing a descriptor that points beyond the allocated memory. This can corrupt arbitrary kernel memory during normal audio data transfer, leading to crashes or a potential privilege escalation if an attacker can influence the data flow.
Affected Systems
Any Linux kernel instance that loads the ALSA usb‑audio driver and interacts with a USB audio device offering a Type II capture format is affected. The issue exists until the kernel is patched to compute the buffer size after accounting for the transfer delimiter packet.
Risk and Exploitability
The EPSS score is below 1 % and the vulnerability is not listed in CISA KEV, but the CVSS score is 7.0. The likely attack vector is a physical or logical attacker who can connect a malicious USB audio device that presents a Type II capture format. An attacker triggering normal capture or playback operations could induce the overflow, potentially allowing arbitrary kernel writes. Exploitation requires access to the USB host controller, so the threat is moderate for systems that process USB audio streams.
OpenCVE Enrichment
Debian DLA
Debian DSA