Executive brief
A vulnerability in the Linux kernel's Apple iSight microphone driver could allow a malicious or faulty FireWire device to cause a system crash or memory corruption. By sending specially crafted data packets, the device can trigger an out-of-bounds read or write during audio capture. This issue primarily affects systems with physical FireWire ports using legacy Apple iSight hardware.
Technical details
An out-of-bounds (OOB) read and write vulnerability exists in the isight_packet() function within sound/firewire/isight.c. The driver takes a sample count directly from the device's isochronous packet header and validates it only against the claimed length, which can be up to 0xffff. Because the internal payload buffer is limited to MAX_FRAMES_PER_PACKET, a large count value causes isight_samples() to read past the payload buffer and potentially write past the PCM DMA area (runtime->dma_area). An attacker with physical access to the FireWire bus could use a malicious device to trigger this memory corruption. The fix introduces an explicit check to ensure the sample count does not exceed MAX_FRAMES_PER_PACKET.
Affected products
- Linux Linux 3a691b28a0ca to 24423e0a9251d348c3f1fb0bb0e61b879e1e976c
Timeline
- 2026-07-25: advisory: CVE-2026-64483 published by NVD
- 2026-07-24: patched: Fix committed to Linux stable tree by Greg Kroah-Hartman
References
- https://git.kernel.org/stable/c/24423e0a9251d348c3f1fb0bb0e61b879e1e976c
- https://git.kernel.org/stable/c/29b9667982e4df2ed7744f86b1144f8bb58eb698
- https://git.kernel.org/stable/c/31a01b70bb90e3ef3147f308e2ea899e1d2485ca
- https://git.kernel.org/stable/c/31da82b9676c6b112e7c72c7529e6812b919742a
- https://git.kernel.org/stable/c/3ed2fa1ed8cc65f910b8bbc0be3cc366b30f8478
- https://git.kernel.org/stable/c/57e4d9043afc1eaddee8f50d11def6e65415d273
- https://git.kernel.org/stable/c/8e48a29813df8dd71503800b7acf69c12c035045