{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-98312","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-25T10:25:14.339Z","datePublished":"2026-10-06T08:46:08.388Z","dateUpdated":"2026-10-06T08:46:08.388Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-10-06T08:46:08.388Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: 6fire: fix OOB write from device-reported iso length\n\nusb6fire_pcm_in_urb_handler() sizes each outgoing isochronous packet as\n(actual_length - 4) / (in_n_analog << 2) * (out_n_analog << 2) + 4, where\nactual_length is the unsigned length the device reported for the matching\nIN packet.  A packet completed with status 0 and actual_length < 4 wraps\nthe subtraction to 0x7fffffec; a zero-length isochronous packet is legal\non the bus, and the preceding loop rejects only non-zero status.  The sum\nreaches memset() on out_urb->buffer, a 4832-byte object from\nkcalloc(PCM_MAX_PACKET_SIZE, PCM_N_PACKETS_PER_URB).\n\nEven without the wrap the result is out of bounds: at 88.2/96 kHz the\n4-in/6-out scaling turns a full 420-byte IN packet into 628, so eight\npackets span 5024 bytes of that buffer.  usb_submit_urb() rejects an\nover-long descriptor only after the memset() and the\nusb6fire_pcm_playback() copy of user PCM data have run.\n\nGuard the subtraction as the sibling usb6fire_pcm_capture() already does,\nand limit the frame count to what fits in rt->out_packet_size, the OUT\nendpoint's wMaxPacketSize.  This bounds total_length by the buffer size\nwhile keeping each packet length aligned to a whole output frame.\n\n  BUG: KASAN: out-of-bounds in usb6fire_pcm_in_urb_handler (sound/usb/6fire/pcm.c:338)\n  Write of size 18446744073709551456 at addr ffff88802a3d0000 by task vhci_rx/5018\n  Call Trace:\n   dump_stack_lvl (lib/dump_stack.c:94 lib/dump_stack.c:120)\n   print_report (mm/kasan/report.c:378 mm/kasan/report.c:482)\n   kasan_report (mm/kasan/report.c:595)\n   kasan_check_range (mm/kasan/generic.c:186 mm/kasan/generic.c:200)\n   __asan_memset (mm/kasan/shadow.c:84)\n   usb6fire_pcm_in_urb_handler (sound/usb/6fire/pcm.c:338)\n   __usb_hcd_giveback_urb (drivers/usb/core/hcd.c:1657)\n   usb_hcd_giveback_urb (drivers/usb/core/hcd.c:1741)\n   vhci_rx_loop (drivers/usb/usbip/vhci_rx.c:107 drivers/usb/usbip/vhci_rx.c:242)\n   kthread (kernel/kthread.c:436)\n   ret_from_fork (arch/x86/kernel/process.c:158)\n   ret_from_fork_asm (arch/x86/entry/entry_64.S:245)\n\n  Allocated by task 10:\n   __kmalloc_cache_noprof (mm/slub.c:5563)\n   usb6fire_pcm_init (sound/usb/6fire/pcm.c:560 sound/usb/6fire/pcm.c:595)\n   usb6fire_chip_probe (sound/usb/6fire/chip.c:133)\n   usb_probe_interface (drivers/usb/core/driver.c:399)\n\n  The buggy address belongs to the object at ffff88802a3d0000\n   which belongs to the cache kmalloc-8k of size 8192\n  The buggy address is located 0 bytes inside of\n   4832-byte region [ffff88802a3d0000, ffff88802a3d12e0)\n  Kernel panic - not syncing: Fatal exception in interrupt"}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["sound/usb/6fire/pcm.c"],"versions":[{"version":"c6d43ba816d1cf1d125bfbfc938f2a28a87facf9","lessThan":"61e665fb48e9eee44ec6d610514af383b1802cc1","status":"affected","versionType":"git"},{"version":"c6d43ba816d1cf1d125bfbfc938f2a28a87facf9","lessThan":"246de677552fe5dede293a1543b632e9853f31e4","status":"affected","versionType":"git"},{"version":"c6d43ba816d1cf1d125bfbfc938f2a28a87facf9","lessThan":"001ba7c1d9677225a5ecbc3e60d4865c08bb21d8","status":"affected","versionType":"git"},{"version":"c6d43ba816d1cf1d125bfbfc938f2a28a87facf9","lessThan":"ea11ade10583cc45af515d6b24510dbfa0184ca6","status":"affected","versionType":"git"},{"version":"c6d43ba816d1cf1d125bfbfc938f2a28a87facf9","lessThan":"cdc31537012bc7a58c95c6750db321b69dd802bb","status":"affected","versionType":"git"},{"version":"c6d43ba816d1cf1d125bfbfc938f2a28a87facf9","lessThan":"1589afe2d099d3e817873bc474676968d7080410","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["sound/usb/6fire/pcm.c"],"versions":[{"version":"2.6.39","status":"affected"},{"version":"0","lessThan":"2.6.39","status":"unaffected","versionType":"semver"},{"version":"6.1.189","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.158","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.112","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.54","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.8","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc4","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.39","versionEndExcluding":"6.1.189"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.39","versionEndExcluding":"6.6.158"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.39","versionEndExcluding":"6.12.112"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.39","versionEndExcluding":"6.18.54"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.39","versionEndExcluding":"7.2.8"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"2.6.39","versionEndExcluding":"7.3-rc4"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/61e665fb48e9eee44ec6d610514af383b1802cc1"},{"url":"https://git.kernel.org/stable/c/246de677552fe5dede293a1543b632e9853f31e4"},{"url":"https://git.kernel.org/stable/c/001ba7c1d9677225a5ecbc3e60d4865c08bb21d8"},{"url":"https://git.kernel.org/stable/c/ea11ade10583cc45af515d6b24510dbfa0184ca6"},{"url":"https://git.kernel.org/stable/c/cdc31537012bc7a58c95c6750db321b69dd802bb"},{"url":"https://git.kernel.org/stable/c/1589afe2d099d3e817873bc474676968d7080410"}],"title":"ALSA: 6fire: fix OOB write from device-reported iso length","x_generator":{"engine":"bippy-1.2.0"}}}}