Executive brief
A vulnerability in the Linux kernel's USB audio driver allows a malicious or noncompliant USB device to write data beyond allocated buffer boundaries during audio capture. An attacker with physical access to connect a specially crafted USB device could trigger memory corruption, potentially leading to kernel crashes or data corruption on affected systems.
Technical details
The vulnerability is an out-of-bounds write in ALSA's USB audio endpoint driver. The root cause is a logic error in data_ep_set_params() where the buffer size is calculated before incrementing the packet count for Format Type II transfer delimiters, but the URB is built with the incremented packet count. This mismatch causes prepare_inbound_urb() to configure the last ISO frame descriptor to point beyond the allocated buffer. When the host controller receives inbound transfers on Type II capture endpoints, it writes device data to this out-of-bounds location. The vulnerability is triggered automatically when userspace calls hw_params on a Type II capture stream from a device advertising such a format. No authentication or special privileges are required beyond the ability to connect a USB device; exploitation occurs at the kernel level via KASAN-detected memory corruption.
Affected products
- Linux Linux kernel 7.2.0-rc5 and likely other versions
Timeline
- 2026-08-22: disclosed