CVE-2026-74682

Source
https://cve.org/CVERecord?id=CVE-2026-74682
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74682.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-74682
Downstream
Published
2026-08-22T15:32:49.527Z
Modified
2026-08-24T11:47:20.599044126Z
Summary
ALSA: usb-audio: fix OOB write on Type II inbound URBs
Details

In the Linux kernel, the following vulnerability has been resolved:

ALSA: usb-audio: fix OOB write on Type II inbound URBs

dataepset_params() sizes each URB transfer buffer before it adds the Format Type II transfer delimiter:

u->packets = urb_packs;
u->buffer_size = maxsize * u->packets;

if (fmt->fmt_type == UAC_FORMAT_TYPE_II)
    u->packets++; /* for transfer delimiter */
u->urb = usb_alloc_urb(u->packets, GFP_KERNEL);

buffer_size is computed from the pre-increment packet count and never recomputed, so for a Type II endpoint the buffer is one packet short of the packet count the URB is built with.

prepareinboundurb() then lays out one iso frame per packet and never consults buffer_size:

offs = 0;
for (i = 0; i < urb_ctx->packets; i++) {
    urb->iso_frame_desc[i].offset = offs;
    urb->iso_frame_desc[i].length = ep->curpacksize;
    offs += ep->curpacksize;
}

urb->transfer_buffer_length = offs;
urb->number_of_packets = urb_ctx->packets;

The last descriptor therefore points one packet past the end of the transfer buffer, where the host controller writes device data on every inbound transfer. preparesilenturb() and prepareplaybackurb() bound their fill loops by ctx->buffer_size, so only capture is affected.

fmttype comes from the device's audio streaming descriptors, so any device advertising a Type II capture format hits this once userspace sets hwparams on the stream.

KASAN on 7.2.0-rc5 (arm64) with a dummy_hcd/raw-gadget device, one report per inbound transfer:

BUG: KASAN: slab-out-of-bounds in dummy_timer Write of size 64 at addr ffff0000186171c0 by task cons02/166 __asanmemcpy dummytimer hrtimerrunsoftirq Allocated by task 166: usballoccoherent sndusbendpointsetparams The buggy address is located 0 bytes to the right of allocated 64-byte region [ffff000018617180, ffff0000186171c0)

Compute buffersize after the delimiter packet has been accounted for, and bound the fill loop by buffersize, as preparesilenturb() already does on the outbound side. This grows every Type II URB allocation by one maxsize packet.

Discovered by XBOW, triaged by Baul Lee baul.lee@xbow.com

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/74xxx/CVE-2026-74682.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
8fdff6a319e7dac757c558bd283dc4577e68cde7
Fixed
6af5f29af7711233ae68d3b25c15d67478468900
Fixed
f1fbb50b99311b35c2e85cc70341d62082dca4b5
Fixed
137bf034740e5a2734794908d0aff1e0bd7cee6e
Fixed
6607f85242577f33d4540a0d1f4a6137f5367058
Fixed
ca22c94bdfc22c564ca2e11c87ba4d17ebeaaa9a
Fixed
0a235379825e1a6194e43861ee6658e5fc35686d
Fixed
d3ed4e6321bb453757044cb9e5ecb30a33f04903
Fixed
69ee44e1a23be62318189dc4b37fa4ad94053269

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74682.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.5.0
Fixed
5.10.265
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.216
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.183
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.152
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.104
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.45
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74682.json"