Executive brief
A vulnerability was identified in the Linux kernel's USB audio driver. This component is responsible for managing audio devices connected via USB. An attacker could potentially exploit this flaw to cause a system crash or instability when a specially crafted USB audio device is processed by the system.
Technical details
An out-of-bounds write vulnerability (CWE-787) exists in the ALSA usb-audio driver within the Linux kernel, specifically in the `convert_chmap` function in `sound/usb/stream.c`. The root cause is a failure to validate the number of channel bits set by a USB audio device against the allocated size of the channel map array. If a device reports more bits than the actual number of channels, the driver continues to write to the `chmap->map` array beyond its bounds. This is a local attack vector requiring the ability to interact with USB device descriptors. The vulnerability has been patched in various stable kernel branches by adding a check to stop parsing once the expected number of channels is reached.
Affected products
- Linux Linux Kernel 3.8 to 4.19.311, 4.20 to 5.4.273, 5.5 to 5.10.214, 5.11 to 5.15.153, 5.16 to 6.1.83, 6.2 to 6.6.23, 6.7 to 6.7.11, 6.8 to 6.8.2
Timeline
- 2024-03-13: other: Vulnerability fixed in source code
- 2024-05-17: disclosed: Initial publication date
References
- https://git.kernel.org/stable/c/22cad1b841a63635a38273b799b4791f202ade72
- https://git.kernel.org/stable/c/5cd466673b34bac369334f66cbe14bb77b7d7827
- https://git.kernel.org/stable/c/629af0d5fe94a35f498ba2c3f19bd78bfa591be6
- https://git.kernel.org/stable/c/6d5dc96b154be371df0d62ecb07efe400701ed8a
- https://git.kernel.org/stable/c/6d88b289fb0a8d055cb79d1c46a56aba7809d96d
- https://git.kernel.org/stable/c/7e2c1b0f6dd9abde9e60f0f9730026714468770f
- https://git.kernel.org/stable/c/9af1658ba293458ca6a13f70637b9654fa4be064