{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-80973","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-08-26T14:34:25.810Z","datePublished":"2026-09-11T19:42:35.751Z","dateUpdated":"2026-09-14T11:59:20.322Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-14T11:59:20.322Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: 6fire: bound the MIDI event length from the device\n\nusb6fire_comm_receiver_handler() forwards a MIDI event using a length\nbyte the device supplies, with no bound and no check that the transfer\ndelivered that many bytes:\n\n\tif (!urb->status) {\n\t\tif (rt->receiver_buffer[0] == 0x10) /* midi in event */\n\t\t\tif (midi_rt)\n\t\t\t\tmidi_rt->in_received(midi_rt,\n\t\t\t\t\t\trt->receiver_buffer + 2,\n\t\t\t\t\t\trt->receiver_buffer[1]);\n\t}\n\nreceiver_buffer is a 64-byte kzalloc() buffer (COMM_RECEIVER_BUFSIZE), so\nonly 62 bytes follow the two-byte header.  receiver_buffer[1] is a u8 the\ndevice chooses, so a device that answers with 0x10 and a length of 0xFF\nmakes snd_rawmidi_receive() read 255 bytes starting two bytes into a\n64-byte object.  The bytes past the buffer are handed to userspace\nthrough the rawmidi read path.\n\nurb->actual_length is not consulted either, so a short transfer leaves\nboth the type byte and the length byte at their previous values and the\nhandler acts on stale data.\n\nThe receiver URB is submitted from usb6fire_comm_init() at probe, so the\nread happens on plug with no user action; forwarding to userspace also\nneeds a MIDI input substream open, since usb6fire_midi_in_received()\nonly calls snd_rawmidi_receive() when rt->in is set.\n\nKASAN on 7.2.0-rc5 (arm64), single packet from an emulated device:\n\n  BUG: KASAN: slab-out-of-bounds in snd_rawmidi_receive\n  Read of size 255 at addr ffff000009f64682 by task bash/183\n   __asan_memcpy\n   snd_rawmidi_receive\n   usb6fire_midi_in_received [snd_usb_6fire]\n   usb6fire_comm_receiver_handler [snd_usb_6fire]\n  Allocated by task 11:\n   usb6fire_comm_init [snd_usb_6fire]\n   usb6fire_chip_probe [snd_usb_6fire]\n  The buggy address is located 2 bytes inside of\n   allocated 64-byte region [ffff000009f64680, ffff000009f646c0)\n\nReject the event when the length exceeds the bytes that follow the\nheader, and require the transfer to have delivered the header plus that\nmany bytes.  The receiver URB is submitted with a 64-byte\ntransfer_buffer_length, so a genuine device cannot deliver an event\nlonger than those 62 bytes and nothing valid is dropped.\n\nDiscovered by XBOW, triaged by Baul Lee <baul.lee@xbow.com>"}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["sound/usb/6fire/comm.c"],"versions":[{"version":"c6d43ba816d1cf1d125bfbfc938f2a28a87facf9","lessThan":"c9204bc2ed2010e2469dbe5fce598878a37efd04","status":"affected","versionType":"git"},{"version":"c6d43ba816d1cf1d125bfbfc938f2a28a87facf9","lessThan":"2c590d5e1b1595d5c8fa0b72d2897423ce9985ca","status":"affected","versionType":"git"},{"version":"c6d43ba816d1cf1d125bfbfc938f2a28a87facf9","lessThan":"0c8a3c773823cf12abd39c480aed70e25c384630","status":"affected","versionType":"git"},{"version":"c6d43ba816d1cf1d125bfbfc938f2a28a87facf9","lessThan":"00e84a9ff2d43953ae261995cae94d46f4c307a6","status":"affected","versionType":"git"},{"version":"c6d43ba816d1cf1d125bfbfc938f2a28a87facf9","lessThan":"466e911bbbbb779bb06337e35a286e5ca7af16b3","status":"affected","versionType":"git"},{"version":"c6d43ba816d1cf1d125bfbfc938f2a28a87facf9","lessThan":"2a6f6fba3bd31d2e8c957fefa29156e35e5e75d5","status":"affected","versionType":"git"},{"version":"c6d43ba816d1cf1d125bfbfc938f2a28a87facf9","lessThan":"34816e2cfeabafb8eccf54687186ce25699e8363","status":"affected","versionType":"git"},{"version":"c6d43ba816d1cf1d125bfbfc938f2a28a87facf9","lessThan":"a478893b59e36cfe7d77a76b352f2db55502e879","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["sound/usb/6fire/comm.c"],"versions":[{"version":"2.6.39","status":"affected"},{"version":"0","lessThan":"2.6.39","status":"unaffected","versionType":"semver"},{"version":"5.10.270","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.221","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.188","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.157","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.109","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.50","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.4","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.39","versionEndExcluding":"5.10.270"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.39","versionEndExcluding":"5.15.221"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.39","versionEndExcluding":"6.1.188"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.39","versionEndExcluding":"6.6.157"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.39","versionEndExcluding":"6.12.109"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.39","versionEndExcluding":"6.18.50"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.39","versionEndExcluding":"7.2.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.39","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/c9204bc2ed2010e2469dbe5fce598878a37efd04"},{"url":"https://git.kernel.org/stable/c/2c590d5e1b1595d5c8fa0b72d2897423ce9985ca"},{"url":"https://git.kernel.org/stable/c/0c8a3c773823cf12abd39c480aed70e25c384630"},{"url":"https://git.kernel.org/stable/c/00e84a9ff2d43953ae261995cae94d46f4c307a6"},{"url":"https://git.kernel.org/stable/c/466e911bbbbb779bb06337e35a286e5ca7af16b3"},{"url":"https://git.kernel.org/stable/c/2a6f6fba3bd31d2e8c957fefa29156e35e5e75d5"},{"url":"https://git.kernel.org/stable/c/34816e2cfeabafb8eccf54687186ce25699e8363"},{"url":"https://git.kernel.org/stable/c/a478893b59e36cfe7d77a76b352f2db55502e879"}],"title":"ALSA: 6fire: bound the MIDI event length from the device","x_generator":{"engine":"bippy-1.2.0"}}}}