Description
In the Linux kernel, the following vulnerability has been resolved:

ALSA: FCP: do not copy out an uninitialised init response

fcp_ioctl_init() allocates its response buffer with kmalloc() and copies
the whole buffer back to userspace:

buf_size = init.step0_resp_size + init.step2_resp_size;

void *resp __free(kfree) =
kmalloc(buf_size, GFP_KERNEL);
...
if (copy_to_user(arg->resp, resp, buf_size))
return -EFAULT;

Nothing clears the buffer, and the only writer of its leading
step0_resp_size bytes is the step-0 control transfer:

err = snd_usb_ctl_msg(dev, usb_rcvctrlpipe(dev, 0),
FCP_USB_REQ_STEP0,
USB_RECIP_INTERFACE | USB_TYPE_CLASS | USB_DIR_IN,
0, private->bInterfaceNumber,
step0_resp, private->step0_resp_size);
if (err < 0)
return err;

usb_fill_control_urb() does not set URB_SHORT_NOT_OK, so a short or
zero-length data stage completes with status 0 and snd_usb_ctl_msg()
returns a small actual_length. The only check is err < 0, so a short
transfer is accepted as success.

snd_usb_ctl_msg() copies the full size back unconditionally:

buf = kmemdup(data, size, GFP_KERNEL);
...
memcpy(data, buf, size);

Bytes the device never wrote are therefore restored into resp unchanged
and copied to userspace. step0_resp_size and step2_resp_size are each
validated only to 1..255, so the caller also picks the slab cache, from
kmalloc-8 up to kmalloc-512.

On 7.2.0-rc5 (arm64), device answering step 0 with a zero-length data
stage, s0 = s2 = 255:

# init_on_alloc off, no spray
step0 window [0,255): nonzero=94/255
000: 00 80 60 06 00 00 ff ff 18 00 00 00 57 01 ea 01
010: 08 78 22 13 00 00 ff ff a8 c4 5f 80 00 80 ff ff

# same kernel, kmalloc-512 pre-seeded with an 8-byte tag
step0 window [0,255): nonzero=219/255 tagbytes=232

# identical run, init_on_alloc=1
step0 window [0,255): nonzero=0/255 tagbytes=0

# all three runs
step2 window [255,510): device words matched=62/62

a8 c4 5f 80 00 80 ff ff is the little-endian kernel text address
ffff8000805fc4a8. The step-2 window is unaffected, so the disclosure is
exactly the step-0 region.

Zero the buffer, and require the step-0 transfer to deliver the full
step0_resp_size bytes so a short data stage is reported as an error.

Discovered by XBOW, triaged by Baul Lee <baul.lee@xbow.com>
Published: 2026-09-11
Score: 4.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Apply Patch
AI Analysis

Impact

In the Linux kernel ALSA FCP handler, an ioctl operation allocates a response buffer that is never initialized before copying it back to user space. The driver accepts a short or zero‑length USB control transfer, which the kernel then retains in the allocated slab. An attacker can thus read kernel memory contents, including addresses, leaking sensitive information. Based on the description, it is inferred that an attacker who can trigger the ioctl can read kernel memory, resulting in information disclosure.

Affected Systems

The Linux kernel is the affected patch is vulnerable. Distributions that have not applied the fix remain exposed even if they are recent official releases.

Risk and Exploitability

The CVSS score of 4.5 indicates a low severity, the EPSS score is < 1%, and the vulnerability is not listed in KEV, suggesting a low exploitation probability. Based on the description, it is inferred that an attacker can trigger the ioctl from a local user interacting with a USB audio device; the likely attack vector is a local user interacting with a malicious or misbehaving USB audio device that triggers the ALSA FCP ioctl, with the attacker gaining read access to kernel memory through the uninitialized buffer copy.

Generated by OpenCVE AI on September 21, 2026 at 03:10 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that includes the fix for the uninitialized memory copy.
  • If an upgrade is not immediately possible, block the ALSA FCP interface by unloading the snd_fcp module (modprobe -r snd_fcp) or by adding a udev rule that denies access to the corresponding /dev/snd/ device until the patch is installed.
  • Reduce risk from malicious USB audio devices by configuring USB device authorization or by restricting the use of ALSA FCP to trusted devices only.

Generated by OpenCVE AI on September 21, 2026 at 03:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 12:30:00 +0000


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-908
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.5, 'vector': 'CVSS:3.1/AV:P/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: ALSA: FCP: do not copy out an uninitialised init response fcp_ioctl_init() allocates its response buffer with kmalloc() and copies the whole buffer back to userspace: buf_size = init.step0_resp_size + init.step2_resp_size; void *resp __free(kfree) = kmalloc(buf_size, GFP_KERNEL); ... if (copy_to_user(arg->resp, resp, buf_size)) return -EFAULT; Nothing clears the buffer, and the only writer of its leading step0_resp_size bytes is the step-0 control transfer: err = snd_usb_ctl_msg(dev, usb_rcvctrlpipe(dev, 0), FCP_USB_REQ_STEP0, USB_RECIP_INTERFACE | USB_TYPE_CLASS | USB_DIR_IN, 0, private->bInterfaceNumber, step0_resp, private->step0_resp_size); if (err < 0) return err; usb_fill_control_urb() does not set URB_SHORT_NOT_OK, so a short or zero-length data stage completes with status 0 and snd_usb_ctl_msg() returns a small actual_length. The only check is err < 0, so a short transfer is accepted as success. snd_usb_ctl_msg() copies the full size back unconditionally: buf = kmemdup(data, size, GFP_KERNEL); ... memcpy(data, buf, size); Bytes the device never wrote are therefore restored into resp unchanged and copied to userspace. step0_resp_size and step2_resp_size are each validated only to 1..255, so the caller also picks the slab cache, from kmalloc-8 up to kmalloc-512. On 7.2.0-rc5 (arm64), device answering step 0 with a zero-length data stage, s0 = s2 = 255: # init_on_alloc off, no spray step0 window [0,255): nonzero=94/255 000: 00 80 60 06 00 00 ff ff 18 00 00 00 57 01 ea 01 010: 08 78 22 13 00 00 ff ff a8 c4 5f 80 00 80 ff ff # same kernel, kmalloc-512 pre-seeded with an 8-byte tag step0 window [0,255): nonzero=219/255 tagbytes=232 # identical run, init_on_alloc=1 step0 window [0,255): nonzero=0/255 tagbytes=0 # all three runs step2 window [255,510): device words matched=62/62 a8 c4 5f 80 00 80 ff ff is the little-endian kernel text address ffff8000805fc4a8. The step-2 window is unaffected, so the disclosure is exactly the step-0 region. Zero the buffer, and require the step-0 transfer to deliver the full step0_resp_size bytes so a short data stage is reported as an error. Discovered by XBOW, triaged by Baul Lee <baul.lee@xbow.com>
Title ALSA: FCP: do not copy out an uninitialised init response
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-14T11:59:17.143Z

Reserved: 2026-08-26T14:34:25.810Z

Link: CVE-2026-80970

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:03.090

Modified: 2026-09-14T13:18:51.770

Link: CVE-2026-80970

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:42:33Z

Links: CVE-2026-80970 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T03:15:09Z

Weaknesses
  • CWE-908

    Use of Uninitialized Resource