All of lore.kernel.org
 help / color / mirror / Atom feed
* CVE-2026-72446: ALSA: usb-audio: qcom: reject stream disable with no active interface
@ 2026-08-15  6:08 Greg Kroah-Hartman
  0 siblings, 0 replies; only message in thread
From: Greg Kroah-Hartman @ 2026-08-15  6:08 UTC (permalink / raw)
  To: linux-cve-announce; +Cc: Greg Kroah-Hartman

From: Greg Kroah-Hartman <gregkh@kernel.org>

Description
===========

In the Linux kernel, the following vulnerability has been resolved:

ALSA: usb-audio: qcom: reject stream disable with no active interface

handle_uaudio_stream_req() resolves an interface index with
info_idx_from_ifnum(), which returns -EINVAL when no interface matches.
The enable branch and the response: cleanup label both guard against a
negative index, but the disable branch does not: it forms
info = &uadev[pcm_card_num].info[info_idx] and dereferences it.

uadev[].info is a pointer allocated only when a stream is first enabled,
so a negative info_idx on the disable path is unsafe in two ways:

 - If the card was never enabled, .info is NULL and &info[-EINVAL] is a
   wild pointer; reading info->data_ep_pipe faults (kernel oops).

 - If the card was enabled at least once (.info allocated) and the
   disable names an interface that does not match, &info[-EINVAL] points
   before the allocation; info->data_ep_pipe / info->sync_ep_pipe are an
   out-of-bounds slab read and, when non-zero, an out-of-bounds 4-byte
   write (both pipe fields are cleared to 0). That is memory corruption,
   not just a NULL dereference.

The request is reachable from unprivileged local userspace over
AF_QIPCRTR. Reject a disable request with no resolved interface, matching
the guard the enable path already has.

The Linux kernel CVE team has assigned CVE-2026-72446 to this issue.


Affected and fixed versions
===========================

	Issue introduced in 6.16 with commit 326bbc348298ab0946c5560defe024a5f6ef28bb and fixed in 6.18.40 with commit 25a867aa5e67a84333fa6e5c21292c5bcff86b90
	Issue introduced in 6.16 with commit 326bbc348298ab0946c5560defe024a5f6ef28bb and fixed in 7.1.5 with commit a22356d1f731553e99aa2707dbd38c659bdd28d8
	Issue introduced in 6.16 with commit 326bbc348298ab0946c5560defe024a5f6ef28bb and fixed in 7.2-rc1 with commit bdb640be82e645e2828731648f485224d0c2587b

Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.

Unaffected versions might change over time as fixes are backported to
older supported kernel versions.  The official CVE entry at
	https://cve.org/CVERecord/?id=CVE-2026-72446
will be updated if fixes are backported, please check that for the most
up to date information about this issue.


Affected files
==============

The file(s) affected by this issue are:
	sound/usb/qcom/qc_audio_offload.c


Mitigation
==========

The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes.  Individual
changes are never tested alone, but rather are part of a larger kernel
release.  Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all.  If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
	https://git.kernel.org/stable/c/25a867aa5e67a84333fa6e5c21292c5bcff86b90
	https://git.kernel.org/stable/c/a22356d1f731553e99aa2707dbd38c659bdd28d8
	https://git.kernel.org/stable/c/bdb640be82e645e2828731648f485224d0c2587b

^ permalink raw reply	[flat|nested] only message in thread

only message in thread, other threads:[~2026-08-15  6:28 UTC | newest]

Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-15  6:08 CVE-2026-72446: ALSA: usb-audio: qcom: reject stream disable with no active interface Greg Kroah-Hartman

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.