CVE-2026-80829: ALSA: usb-audio: fix OOB write in snd_usbmidi_novation_output()
ALSA: usb-audio: fix OOB write in sndusbmidinovationoutput()
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.6.157.1-1
Event History
Frequently Asked Questions
What must an attacker control to trigger this issue?
An attacker needs a malformed or malicious USB device that advertises a bulk OUT endpoint with a wMaxPacketSize of 1. When the system uses the affected Novation USB-MIDI output path, that value causes a negative transmit length and an out-of-bounds write.
How can I determine whether a system is exposed?
Exposure depends on running a Linux kernel with the ALSA usb-audio driver and connecting a device that can present the malformed bulk OUT endpoint descriptor. The provided data does not identify affected kernel versions; compare the kernel's applied fixes with the referenced stable commits.
What is the risk if the issue is triggered?
The negative length is converted to a size_t value of -1 for memcpy, causing a write far beyond the USB transfer buffer. This is a kernel memory-safety issue.