CVE-2026-74502: ALSA: ump: fix double free of out_cvts on rawmidi error
In the Linux kernel, the following vulnerability has been resolved:
ALSA: ump: fix double free of outcvts on rawmidi error
sndumpattachlegacyrawmidi() allocates the legacy conversion array ump->outcvts and, on the sndrawmidinew() error path, frees it with kfree() but leaves ump->outcvts pointing at the freed memory. When the endpoint is later torn down, sndumpendpointfree() frees ump->outcvts a second time, resulting in a double free.
The host snd-usb-audio driver attaches the legacy rawmidi for any USB MIDI 2.0 (UMP) device, so a device that makes sndrawmidinew() fail reaches this path on enumeration.
Clear ump->outcvts after freeing it on the error path so it is not freed again during teardown.
Discovered by XBOW, triaged by Baul Lee <baul.lee@xbow.com>
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-74502?
CVE-2026-74502 has a risk score of 37, indicating a moderate security threat.
How do I fix CVE-2026-74502?
To fix CVE-2026-74502, upgrade to the patched version of the Linux kernel that addresses the double free vulnerability.
What systems are affected by CVE-2026-74502?
CVE-2026-74502 affects Linux kernel versions utilizing ALSA with legacy rawmidi support.
What type of vulnerability is CVE-2026-74502?
CVE-2026-74502 is classified as a double free vulnerability, which may lead to software crashes or potential exploitation.
When was CVE-2026-74502 published?
CVE-2026-74502 was published on August 15, 2026.