CVE-2026-52963
Description
In the Linux kernel, the following vulnerability has been resolved:
ALSA: usb-audio: Bound MIDI endpoint descriptor scans
snd_usbmidi_get_ms_info() validates the internal MIDIStreaming endpoint
descriptor size before using baAssocJackID[], but the descriptor walker can
still return a class-specific endpoint descriptor whose bLength exceeds the
remaining bytes in the endpoint-extra scan.
That leaves later flexible-array reads bounded by bLength, but not by the
remaining bytes in the endpoint-extra scan.
Stop walking when bLength is zero or
extends past the remaining endpoint-extra scan.
Summary dbcve.org
Out-of-bounds read vulnerability in Linux kernel's ALSA USB audio driver where snd_usbmidi_get_ms_info() doesn't validate that MIDI endpoint descriptor bLength doesn't exceed remaining bytes in the endpoint-extra buffer before performing flexible-array reads, allowing access beyond buffer boundaries.
Mitigation
Apply Linux kernel patch to add bounds checking that stops the descriptor walk when bLength is zero or extends past the remaining endpoint-extra scan; typically delivered via kernel updates.