Executive brief
The Linux kernel's ALSA audio subsystem contains a memory handling bug in the TASCAM US-144MkII USB audio interface driver. When the device is disconnected or the audio system is shut down, previously submitted USB requests (URBs) may still be queued on the controller after the driver's memory is freed. This can result in memory corruption and system crashes when the device attempts to complete these stale requests.
Technical details
The vulnerability is a use-after-free in the ALSA us144mkii driver's capture URB completion handler. When capture_urb_complete() resubmits URBs, it increments the reference count and resubmits without re-anchoring the URB to the capture anchor. Since USB anchoring is a per-submission property (not a URB property), the URB is automatically unanchored by the USB core during giveback before the completion handler runs. This causes tascam->capture_anchor to become empty after the first completion, rendering usb_kill_anchored_urbs() ineffective on disconnect/suspend/stop paths. Consequently, URBs remain queued on the host controller while tascam_free_urbs() releases the transfer buffer memory and snd_card_free() releases the driver object. When the controller later completes these queued URBs, the handler writes to freed memory and dereferences a freed driver object. The fix restores usb_anchor_urb() between the reference count increment and resubmission to maintain proper URB tracking through the anchor mechanism.
Affected products
- Linux Linux kernel 7.2.0-rc5 and earlier (ALSA us144mkii driver)
Timeline
- 2026-08-22: disclosed