Fedora Account System
Red Hat Associate
Red Hat Customer
In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Add sanity check for OOB writes at silencing At silencing the playback URB packets in the implicit fb mode before the actual playback, we blindly assume that the received packets fit with the buffer size. But when the setup in the capture stream differs from the playback stream (e.g. due to the USB core limitation of max packet size), such an inconsistency may lead to OOB writes to the buffer, resulting in a crash. For addressing it, add a sanity check of the transfer buffer size at prepare_silent_urb(), and stop the data copy if the received data overflows. Also, report back the transfer error properly from there, too. Note that this doesn't fix the root cause of the playback error itself, but this merely covers the kernel Oops.
Upstream advisory: https://lore.kernel.org/linux-cve-announce/2026050613-CVE-2026-43279-4530@gregkh/T
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:27354 https://access.redhat.com/errata/RHSA-2026:27354
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:27353 https://access.redhat.com/errata/RHSA-2026:27353
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:27789 https://access.redhat.com/errata/RHSA-2026:27789
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:33685 https://access.redhat.com/errata/RHSA-2026:33685
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2026:33900 https://access.redhat.com/errata/RHSA-2026:33900
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2026:34095 https://access.redhat.com/errata/RHSA-2026:34095
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions Red Hat Enterprise Linux 8.8 Telecommunications Update Service Via RHSA-2026:35863 https://access.redhat.com/errata/RHSA-2026:35863
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On Via RHSA-2026:35894 https://access.redhat.com/errata/RHSA-2026:35894
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions Via RHSA-2026:36767 https://access.redhat.com/errata/RHSA-2026:36767
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:38902 https://access.redhat.com/errata/RHSA-2026:38902
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Extended Lifecycle Support Via RHSA-2026:44522 https://access.redhat.com/errata/RHSA-2026:44522
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Extended Lifecycle Support Via RHSA-2026:46461 https://access.redhat.com/errata/RHSA-2026:46461
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On Via RHSA-2026:47633 https://access.redhat.com/errata/RHSA-2026:47633
This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:55445 https://access.redhat.com/errata/RHSA-2026:55445