In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: fix OOB write on Type II inbound URBs data_ep_set_params()… (CVE-2026-74682)
A vulnerability in the Linux kernel ALSA usb-audio driver caused an out-of-bounds write on Type II inbound USB Request Blocks (URBs). The issue arises because the buffer size for URB transfers is calculated before incrementing the packet count for the transfer delimiter, leading to a buffer that is one packet too small. This results in the last iso frame descriptor pointing past the end of the allocated buffer, causing out-of-bounds writes during inbound audio capture streams. The flaw affects devices advertising a Type II capture format and is triggered when userspace sets hardware parameters on the stream. The vulnerability has been resolved by adjusting the buffer size calculation and bounding the fill loop accordingly.
AI Analysis
Technical Summary
The Linux kernel ALSA usb-audio driver had a flaw in data_ep_set_params() where the buffer_size for URB transfers was computed before incrementing the packet count for the Type II transfer delimiter. Consequently, the allocated buffer was one packet short. During inbound URB preparation, the iso frame descriptors were set up for the incremented packet count, causing the last descriptor to point beyond the buffer boundary. This led to out-of-bounds writes on inbound capture transfers for devices using Type II audio formats. The fix involves computing buffer_size after accounting for the delimiter packet and bounding the fill loop by buffer_size, preventing the out-of-bounds write. The issue was discovered by XBOW and triaged by Baul Lee.
Potential Impact
This vulnerability causes an out-of-bounds write in the kernel memory during inbound USB audio capture streams on devices using Type II audio formats. Such memory corruption could potentially lead to system instability, crashes, or escalation of privileges depending on the context and exploitation, though no specific exploit or active attacks are reported. The flaw affects the ALSA usb-audio driver in the Linux kernel and is triggered when userspace sets hardware parameters on affected streams.
Mitigation Recommendations
A fix for this vulnerability has been implemented in the Linux kernel by correcting the buffer size calculation and bounding the fill loop to prevent out-of-bounds writes. Users should update their Linux kernel to a version that includes this patch. Since this is a kernel-level issue, applying the official kernel update from the vendor or distribution is the recommended remediation. Patch status is not explicitly confirmed in the provided data; therefore, check the vendor or Linux kernel advisory for the exact fixed versions and update accordingly.
In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: fix OOB write on Type II inbound URBs data_ep_set_params()… (CVE-2026-74682)
Description
A vulnerability in the Linux kernel ALSA usb-audio driver caused an out-of-bounds write on Type II inbound USB Request Blocks (URBs). The issue arises because the buffer size for URB transfers is calculated before incrementing the packet count for the transfer delimiter, leading to a buffer that is one packet too small. This results in the last iso frame descriptor pointing past the end of the allocated buffer, causing out-of-bounds writes during inbound audio capture streams. The flaw affects devices advertising a Type II capture format and is triggered when userspace sets hardware parameters on the stream. The vulnerability has been resolved by adjusting the buffer size calculation and bounding the fill loop accordingly.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Linux kernel ALSA usb-audio driver had a flaw in data_ep_set_params() where the buffer_size for URB transfers was computed before incrementing the packet count for the Type II transfer delimiter. Consequently, the allocated buffer was one packet short. During inbound URB preparation, the iso frame descriptors were set up for the incremented packet count, causing the last descriptor to point beyond the buffer boundary. This led to out-of-bounds writes on inbound capture transfers for devices using Type II audio formats. The fix involves computing buffer_size after accounting for the delimiter packet and bounding the fill loop by buffer_size, preventing the out-of-bounds write. The issue was discovered by XBOW and triaged by Baul Lee.
Potential Impact
This vulnerability causes an out-of-bounds write in the kernel memory during inbound USB audio capture streams on devices using Type II audio formats. Such memory corruption could potentially lead to system instability, crashes, or escalation of privileges depending on the context and exploitation, though no specific exploit or active attacks are reported. The flaw affects the ALSA usb-audio driver in the Linux kernel and is triggered when userspace sets hardware parameters on affected streams.
Mitigation Recommendations
A fix for this vulnerability has been implemented in the Linux kernel by correcting the buffer size calculation and bounding the fill loop to prevent out-of-bounds writes. Users should update their Linux kernel to a version that includes this patch. Since this is a kernel-level issue, applying the official kernel update from the vendor or distribution is the recommended remediation. Patch status is not explicitly confirmed in the provided data; therefore, check the vendor or Linux kernel advisory for the exact fixed versions and update accordingly.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-f9hx-h75g-5vp2
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-74682"]
- Ecosystems
- []
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a8a27f1acd9273b499bc762
Added to database: 08/22/2026, 22:51:29 UTC
Last enriched: 08/23/2026, 00:24:42 UTC
Last updated: 08/23/2026, 01:52:05 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.