Impact
The vulnerability lies in the Linux kernel’s ALSA USB‑audio driver, specifically the function snd_usbmidi_us122l_output(). The driver incorrectly uses a hard‑coded count of two bytes for non‑high‑speed devices without verifying it against the endpoint’s maximum transfer size. Because the URB buffer is sized to the endpoint’s maximum, a device advertising a single‑byte bulk endpoint can cause the driver to write two bytes into the buffer, resulting in an out‑of‑bounds write. This corrupts kernel memory and may allow a local attacker to manipulate kernel data structures, potentially reaching full kernel compromise.
Affected Systems
All Linux kernel releases that include the ALSA USB‑audio driver before the fix was applied are affected. The vendor is the Linux kernel project itself; no individual corporate vendor is referenced. The affected product is the ALSA USB‑audio module within the kernel.
Risk and Exploitability
The EPSS score of < 1% indicates a very low probability of exploitation in the wild, and the vulnerability is not recorded in the CISA KEV catalog. Nonetheless, memory corruption in the kernel can lead to privilege escalation or denial of service. The likely attack vector is local; an attacker would need access to the system to interact with the USB audio hardware or the ALSA interface to trigger the overflow. No special user privileges are required beyond those needed to load or use the ALSA driver, so the risk to all users of affected systems remains significant until mitigation is applied.
OpenCVE Enrichment
Debian DLA
Debian DSA