Junglewise Threat Intelligence

CVE-2024-27436: Linux Kernel out-of-bounds write in ALSA usb-audio

CVE-2024-27436 · Severity: medium · CVSS 5.5 · Published 2024-05-17

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's USB audio driver. This component is responsible for managing audio devices connected via USB. An attacker could potentially exploit this flaw to cause a system crash or instability when a specially crafted USB audio device is processed by the system.

Technical details

An out-of-bounds write vulnerability (CWE-787) exists in the ALSA usb-audio driver within the Linux kernel, specifically in the `convert_chmap` function in `sound/usb/stream.c`. The root cause is a failure to validate the number of channel bits set by a USB audio device against the allocated size of the channel map array. If a device reports more bits than the actual number of channels, the driver continues to write to the `chmap->map` array beyond its bounds. This is a local attack vector requiring the ability to interact with USB device descriptors. The vulnerability has been patched in various stable kernel branches by adding a check to stop parsing once the expected number of channels is reached.

Affected products

  • Linux Linux Kernel 3.8 to 4.19.311, 4.20 to 5.4.273, 5.5 to 5.10.214, 5.11 to 5.15.153, 5.16 to 6.1.83, 6.2 to 6.6.23, 6.7 to 6.7.11, 6.8 to 6.8.2

Timeline

  • 2024-03-13: other: Vulnerability fixed in source code
  • 2024-05-17: disclosed: Initial publication date

References

Related threats