Bug 2540451 (CVE-2026-93808) - CVE-2026-93808 kernel: ALSA: usb-audio: caiaq: validate EP1 reply lengths
Summary: CVE-2026-93808 kernel: ALSA: usb-audio: caiaq: validate EP1 reply lengths
Keywords:
Status: NEW
Alias: CVE-2026-93808
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-09-24 16:53 UTC by OSIDB Bzimport
Modified: 2026-09-28 12:59 UTC (History)
17 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-09-24 16:53:06 UTC
In the Linux kernel, the following vulnerability has been resolved:

ALSA: usb-audio: caiaq: validate EP1 reply lengths

usb_ep1_command_reply_dispatch() uses buf[0] as a command byte and then
reads command-specific fixed items from the same URB buffer. Several
paths use buf + 1, buf[1], buf[2], or buf + 3 without first proving that
urb->actual_length contains those bytes.

Add per-command length checks, use a payload length derived from the
bytes after the command byte for the control-state copy, and reject short
analog input payloads before the input helper reads fixed offsets from
the EP1 reply.


Note You need to log in before you can comment on or make changes to this bug.