CVE-2026-90033: ALSA: usb-audio: fix OOB write in snd_usbmidi_us122l_output()
ALSA: usb-audio: fix OOB write in sndusbmidius122loutput()
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.6.157.1-1
Event History
Frequently Asked Questions
Which connected devices can trigger the issue?
The vulnerable path can be triggered by a USB MIDI device that declares a one-byte bulk endpoint on a connection slower than USB high speed. The description specifically identifies the US-122MKII (USB ID 0644:8021) as falling through to the default packet-size handling.
What makes the memory corruption occur?
On non-high-speed connections, the output path uses a transmit count of two bytes without ensuring that it fits in the endpoint's max_transfer buffer. With a one-byte endpoint, the subsequent padding calculation underflows and can cause an out-of-bounds write.
Are all affected device IDs handled the same way?
No. Device IDs 0x800e and 0x800f are explicitly pinned to a nine-byte transfer size, while other devices use the default handling based on usb_maxpacket().