Bug 2541134 (CVE-2026-97930) - CVE-2026-97930 kernel: ALSA: usbusx2y: fix in04_last array size mismatch with in04_buf
Summary: CVE-2026-97930 kernel: ALSA: usbusx2y: fix in04_last array size mismatch with...
Keywords:
Status: NEW
Alias: CVE-2026-97930
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-09-25 10:51 UTC by OSIDB Bzimport
Modified: 2026-09-29 20:09 UTC (History)
17 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-09-25 10:51:18 UTC
In the Linux kernel, the following vulnerability has been resolved:

ALSA: usbusx2y: fix in04_last array size mismatch with in04_buf

The in04_last array in struct usx2ydev is declared as char[24], but
in04_buf is allocated as sizeof(struct us428_ctls) which is 21 bytes.
In i_usx2y_in04_int(), when ctl_snapshot_last == -2 (initialization
path):

    memcpy(usx2y->in04_last, usx2y->in04_buf, sizeof(usx2y->in04_last));

This copies 24 bytes from a 21-byte slab allocation, reading 3 bytes
past the end of the source object.

Introduce a USX2Y_IN04_SIZE constant defined as sizeof(struct
us428_ctls) and use it consistently for the in04_last array, the
in04_buf allocation, the URB transfer length, and the comparison loop,
replacing the bare 24 and 21 literals throughout.


Note You need to log in before you can comment on or make changes to this bug.