CVE-2026-90033: ALSA: usb-audio: fix OOB write in snd_usbmidi_us122l_output()

Published Sep 16, 2026
·
Updated

ALSA: usb-audio: fix OOB write in sndusbmidius122loutput()

Affected Software

2 affected componentsFixes available
Linux ALSA (usb-audio)
Microsoft azl3 kernel 6.6.152.1-1<6.6.157.1-1
6.6.157.1-1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 6.6.157.1-1

Event History

Sep 16, 2026
CVE Published
via MITRE·10:33 AM
Data Sourced
via MITRE·10:33 AM
Description
Data Sourced
via NVD·11:17 AM
Description
Sep 17, 2026
Data Sourced
via Microsoft·08:08 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·08:08 AM
Affected Software
Updated
via Microsoft·08:08 AM
DescriptionSeverity

Frequently Asked Questions

1

Which connected devices can trigger the issue?

The vulnerable path can be triggered by a USB MIDI device that declares a one-byte bulk endpoint on a connection slower than USB high speed. The description specifically identifies the US-122MKII (USB ID 0644:8021) as falling through to the default packet-size handling.

2

What makes the memory corruption occur?

On non-high-speed connections, the output path uses a transmit count of two bytes without ensuring that it fits in the endpoint's max_transfer buffer. With a one-byte endpoint, the subsequent padding calculation underflows and can cause an out-of-bounds write.

3

Are all affected device IDs handled the same way?

No. Device IDs 0x800e and 0x800f are explicitly pinned to a nine-byte transfer size, while other devices use the default handling based on usb_maxpacket().

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203