Junglewise Threat Intelligence

CVE-2026-52963: Linux Kernel ALSA out-of-bounds read in USB MIDI descriptor scan

CVE-2026-52963 · Severity: info · CVSS 0 · Published 2026-06-24

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's USB audio driver (ALSA) related to how it handles MIDI devices. An attacker with physical access could potentially use a specially crafted USB MIDI device to cause a system crash or memory corruption by providing invalid device descriptors. This affects systems using Linux-based operating systems when interacting with malicious or malfunctioning USB MIDI hardware.

Technical details

A vulnerability in the ALSA usb-audio component of the Linux kernel arises from insufficient validation in the `snd_usbmidi_get_ms_info()` function and its descriptor walker. While the code validates the MIDIStreaming endpoint descriptor size, the walker can return a class-specific descriptor with a `bLength` value that exceeds the actual remaining bytes in the scan buffer. This results in subsequent flexible-array reads being bounded by the attacker-controlled `bLength` rather than the actual buffer size, leading to an out-of-bounds read. The fix introduces checks to stop the descriptor walk if `bLength` is zero or exceeds the remaining scan length. This typically requires physical access to plug in a malicious USB device.

Affected products

  • Linux Linux Kernel 4.4.238 to 7.1.y

Timeline

  • 2026-05-07: other: Patch submitted by developer
  • 2026-06-24: disclosed: CVE published to NVD

References

Related threats