CVE-2026-72403
N/A
Summary
In the Linux kernel, the following vulnerability has been resolved:
ALSA: FCP: Fix NULL pointer dereference in interface lookup
A malformed USB device can provide a vendor-specific interface without any endpoint descriptors. fcp_find_fc_interface() currently selects the first vendor-specific interface and reads endpoint 0 from it, without checking whether the interface actually has any endpoints.
When bNumEndpoints is zero, no endpoint array is allocated for the parsed alternate setting, so get_endpoint(…, 0) yields an invalid endpoint descriptor pointer. Dereferencing it through usb_endpoint_num() then triggers a NULL pointer dereference.
Skip vendor-specific interfaces that do not have any endpoints.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 46757a3e7d50dac923888e7fbe68377736f13c70 < f28d7b5f1578a7501ab17b10643ed1e4f729187e | affected |
| Linux | Linux | 46757a3e7d50dac923888e7fbe68377736f13c70 < 3ab06151ffcb8c3aeb8f78508658b6c0f05be932 | affected |
| Linux | Linux | 46757a3e7d50dac923888e7fbe68377736f13c70 < e1e31e0ec8a609e17fd2e86b77bc00d9cbb24d7c | affected |
| Linux | Linux | 6.14 | affected |
| Linux | Linux | 0 < 6.14 | unaffected |
| Linux | Linux | 6.18.40 <= 6.18.* | unaffected |
| Linux | Linux | 7.1.5 <= 7.1.* | unaffected |
| Linux | Linux | 7.2 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/f28d7b5f1578a7501ab17b10643ed1e4f729187e
- https://git.kernel.org/stable/c/3ab06151ffcb8c3aeb8f78508658b6c0f05be932
- https://git.kernel.org/stable/c/e1e31e0ec8a609e17fd2e86b77bc00d9cbb24d7c
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.