CVE-2026-64601
N/A
Summary
In the Linux kernel, the following vulnerability has been resolved:
ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on each resubmission
In capture_urb_complete(), usb_anchor_urb() is called on every completion callback, but the URB is already anchored from the initial submission in tascam_trigger_start(). Each redundant call corrupts the anchor's doubly-linked list and inflates the URB refcount. When usb_kill_anchored_urbs() traverses the list during stream stop / suspend / disconnect, the corrupted list leads to use-after-free.
Remove the redundant usb_anchor_urb() from the resubmit path.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | c1bb0c13e430623c26543baae5bb9ae21139db87 < 16f14f55141d4c55c3f321f93c328fff7cd6860a | affected |
| Linux | Linux | c1bb0c13e430623c26543baae5bb9ae21139db87 < ab1db64912428cdf06a4f9542e16e0575e9ad59f | affected |
| Linux | Linux | c1bb0c13e430623c26543baae5bb9ae21139db87 < 5cff1529a2f9b3461a7f5a6e36a86682fc290534 | affected |
| Linux | Linux | 6.18 | affected |
| Linux | Linux | 0 < 6.18 | unaffected |
| Linux | Linux | 6.18.39 <= 6.18.* | unaffected |
| Linux | Linux | 7.1.4 <= 7.1.* | unaffected |
| Linux | Linux | 7.2-rc2 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/16f14f55141d4c55c3f321f93c328fff7cd6860a
- https://git.kernel.org/stable/c/ab1db64912428cdf06a4f9542e16e0575e9ad59f
- https://git.kernel.org/stable/c/5cff1529a2f9b3461a7f5a6e36a86682fc290534
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.