MEDIUM

CVE-2026-52963

Linux Linux Kernel 2026-06-24 CVSS v3.1
CVSS
5.5

Description

In the Linux kernel, the following vulnerability has been resolved:

ALSA: usb-audio: Bound MIDI endpoint descriptor scans

snd_usbmidi_get_ms_info() validates the internal MIDIStreaming endpoint
descriptor size before using baAssocJackID[], but the descriptor walker can
still return a class-specific endpoint descriptor whose bLength exceeds the
remaining bytes in the endpoint-extra scan.

That leaves later flexible-array reads bounded by bLength, but not by the
remaining bytes in the endpoint-extra scan.

Stop walking when bLength is zero or
extends past the remaining endpoint-extra scan.

Summary dbcve.org

Out-of-bounds read vulnerability in Linux kernel's ALSA USB audio driver where snd_usbmidi_get_ms_info() doesn't validate that MIDI endpoint descriptor bLength doesn't exceed remaining bytes in the endpoint-extra buffer before performing flexible-array reads, allowing access beyond buffer boundaries.

Mitigation

Apply Linux kernel patch to add bounds checking that stops the descriptor walk when bLength is zero or extends past the remaining endpoint-extra scan; typically delivered via kernel updates.

Patch Commit

EPSS Score

0.13%
Probability of exploitation in next 30 days
2.8th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE