Description
In the Linux kernel, the following vulnerability has been resolved:

ALSA: usb-audio: fix OOB write in snd_usbmidi_us122l_output()

The snd_usbmidi_us122l_output() picks a count of 2 on anything slower
than high speed and never relates it to ep->max_transfer. The URB
buffer holds exactly max_transfer bytes, so a device declaring a one
byte bulk endpoint takes two bytes from snd_rawmidi_transmit(), and the
memset that pads the rest computes 1 - 2 in int and wraps to SIZE_MAX.

Only 0x800e and 0x800f are pinned to nine bytes. The US-122MKII at
0x0644:0x8021 falls to the default and takes usb_maxpacket(), which the
USB core only clamps downward.

The akai and novation output ops in this file were given the same guard
recently. Do the same here.
Published: 2026-09-16
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Kernel memory corruption leading to potential privilege escalation
Action: Immediate Patch
AI Analysis

Impact

The vulnerability lies in the Linux kernel’s ALSA USB‑audio driver, specifically the function snd_usbmidi_us122l_output(). The driver incorrectly uses a hard‑coded count of two bytes for non‑high‑speed devices without verifying it against the endpoint’s maximum transfer size. Because the URB buffer is sized to the endpoint’s maximum, a device advertising a single‑byte bulk endpoint can cause the driver to write two bytes into the buffer, resulting in an out‑of‑bounds write. This corrupts kernel memory and may allow a local attacker to manipulate kernel data structures, potentially reaching full kernel compromise.

Affected Systems

All Linux kernel releases that include the ALSA USB‑audio driver before the fix was applied are affected. The vendor is the Linux kernel project itself; no individual corporate vendor is referenced. The affected product is the ALSA USB‑audio module within the kernel.

Risk and Exploitability

The EPSS score of < 1% indicates a very low probability of exploitation in the wild, and the vulnerability is not recorded in the CISA KEV catalog. Nonetheless, memory corruption in the kernel can lead to privilege escalation or denial of service. The likely attack vector is local; an attacker would need access to the system to interact with the USB audio hardware or the ALSA interface to trigger the overflow. No special user privileges are required beyond those needed to load or use the ALSA driver, so the risk to all users of affected systems remains significant until mitigation is applied.

Generated by OpenCVE AI on September 18, 2026 at 06:47 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that includes the commit fixing the OOB write in snd_usbmidi_us122l_output()
  • If a kernel update is not immediately available, install the individual patch commits from the kernel source to apply the fix manually
  • After applying the patch or upgrade, disable or blacklist the ALSA usb‑audio module for any devices that may expose a one‑byte bulk endpoint, to eliminate the exploitation surface until a permanent fix is in place

Generated by OpenCVE AI on September 18, 2026 at 06:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Fri, 18 Sep 2026 07:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
CWE-122

Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: fix OOB write in snd_usbmidi_us122l_output() The snd_usbmidi_us122l_output() picks a count of 2 on anything slower than high speed and never relates it to ep->max_transfer. The URB buffer holds exactly max_transfer bytes, so a device declaring a one byte bulk endpoint takes two bytes from snd_rawmidi_transmit(), and the memset that pads the rest computes 1 - 2 in int and wraps to SIZE_MAX. Only 0x800e and 0x800f are pinned to nine bytes. The US-122MKII at 0x0644:0x8021 falls to the default and takes usb_maxpacket(), which the USB core only clamps downward. The akai and novation output ops in this file were given the same guard recently. Do the same here.
Title ALSA: usb-audio: fix OOB write in snd_usbmidi_us122l_output()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T10:33:33.899Z

Reserved: 2026-09-11T19:38:34.782Z

Link: CVE-2026-90033

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:17:16.437

Modified: 2026-09-16T11:17:16.437

Link: CVE-2026-90033

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T07:00:06Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-122

    Heap-based Buffer Overflow