Executive brief
The Linux kernel's USB audio driver for MIDI 2.0 devices contains a memory safety flaw that can cause a system crash when a USB device fails to initialize properly. The vulnerability allows freed memory to be accessed during cleanup, potentially leading to a kernel panic or data corruption on systems using affected audio equipment.
Technical details
This is a use-after-free vulnerability in the ALSA (Advanced Linux Sound Architecture) usb-audio subsystem's MIDI 2.0 implementation. The root cause is that input URBs (USB Request Blocks) submitted during device creation are not properly cancelled before their associated endpoint and buffer memory is freed during error-path cleanup. When a setup failure occurs after URBs have been submitted, the kernel attempts to free endpoint storage and coherent URB buffers without first stopping the URBs. A completion handler running concurrently can then dereference the freed endpoint context and memory, triggering a KASAN slab-use-after-free error. The vulnerability requires a USB device to initiate the probe path and fail during setup, combined with in-flight URB completions. The fix ensures URBs are killed synchronously before freeing endpoint resources, matching the teardown sequence used during normal disconnect.
Affected products
- Linux Linux kernel affected versions not specified in advisory
Timeline
- 2026-08-15: disclosed