Executive brief
A vulnerability in the Linux kernel's audio system (ALSA) could allow a malicious or malfunctioning virtual device to crash the system or access restricted memory. The issue occurs when the system incorrectly trusts data provided by virtual sound hardware, which can lead to memory errors. This primarily affects virtualized environments where the guest operating system interacts with virtualized audio hardware.
Technical details
An out-of-bounds (OOB) access vulnerability exists in the Linux kernel's ALSA virtio-snd driver (sound/virtio/virtio_kctl.c). The driver implicitly trusts device-provided control types and value counts, using them to index the g_v2a_type_map array and to bound loops/memcpy operations against fixed-size virtio_snd_ctl_value and snd_ctl_elem_value arrays. A malicious or buggy virtio device can provide an invalid type or oversized count to trigger OOB reads or writes. The fix introduces validation in virtsnd_kctl_parse_cfg() to ensure metadata conforms to expected bounds before processing.
Affected products
- Linux Linux Kernel 6.9 to 6.12.96, 6.18.39, 7.1.4
Timeline
- 2026-07-25: disclosed: CVE published and patches identified in stable branches.