Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-98312— ALSA: 6fire: fix OOB write from device-reported iso length

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Linux 内核中,已修复以下漏洞: ALSA: 6fire:修复因设备报告的 ISO 长度导致的越界写入 函数 在计算每个出向等时(isochronous)数据包的大小时,使用的公式为: 其中 是设备为匹配的 IN 数据包报告的无符号长度。如果数据包以状态 0 完成,且 ,则减法操作会下溢至 ;而在总线上零长度的等时数据包是合法的,且前一个循环仅拒绝非零状态。该总和最终被传递到 ,写入的是 ,这是一个大小为 4832 字节的对象,由 分配。 即使没有发生下溢,结果仍然越界:在 88.2 kHz 或 96 kH

AI Predicted 7.8 Difficulty: Moderate EPSS 0.18% · P7

Affected Version Matrix 14

VendorProduct Version RangeStatus
Linux Linux c6d43ba816d1cf1d125bfbfc938f2a28a87facf9< 61e665fb48e9eee44ec6d610514af383b1802cc1 affected
c6d43ba816d1cf1d125bfbfc938f2a28a87facf9< 246de677552fe5dede293a1543b632e9853f31e4 affected
c6d43ba816d1cf1d125bfbfc938f2a28a87facf9< 001ba7c1d9677225a5ecbc3e60d4865c08bb21d8 affected
c6d43ba816d1cf1d125bfbfc938f2a28a87facf9< ea11ade10583cc45af515d6b24510dbfa0184ca6 affected
c6d43ba816d1cf1d125bfbfc938f2a28a87facf9< cdc31537012bc7a58c95c6750db321b69dd802bb affected
c6d43ba816d1cf1d125bfbfc938f2a28a87facf9< 1589afe2d099d3e817873bc474676968d7080410 affected
2.6.39 affected
< 2.6.39 unaffected
… +6 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-98312

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
ALSA: 6fire: fix OOB write from device-reported iso length
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: ALSA: 6fire: fix OOB write from device-reported iso length usb6fire_pcm_in_urb_handler() sizes each outgoing isochronous packet as (actual_length - 4) / (in_n_analog << 2) * (out_n_analog << 2) + 4, where actual_length is the unsigned length the device reported for the matching IN packet. A packet completed with status 0 and actual_length < 4 wraps the subtraction to 0x7fffffec; a zero-length isochronous packet is legal on the bus, and the preceding loop rejects only non-zero status. The sum reaches memset() on out_urb->buffer, a 4832-byte object from kcalloc(PCM_MAX_PACKET_SIZE, PCM_N_PACKETS_PER_URB). Even without the wrap the result is out of bounds: at 88.2/96 kHz the 4-in/6-out scaling turns a full 420-byte IN packet into 628, so eight packets span 5024 bytes of that buffer. usb_submit_urb() rejects an over-long descriptor only after the memset() and the usb6fire_pcm_playback() copy of user PCM data have run. Guard the subtraction as the sibling usb6fire_pcm_capture() already does, and limit the frame count to what fits in rt->out_packet_size, the OUT endpoint's wMaxPacketSize. This bounds total_length by the buffer size while keeping each packet length aligned to a whole output frame. BUG: KASAN: out-of-bounds in usb6fire_pcm_in_urb_handler (sound/usb/6fire/pcm.c:338) Write of size 18446744073709551456 at addr ffff88802a3d0000 by task vhci_rx/5018 Call Trace: dump_stack_lvl (lib/dump_stack.c:94 lib/dump_stack.c:120) print_report (mm/kasan/report.c:378 mm/kasan/report.c:482) kasan_report (mm/kasan/report.c:595) kasan_check_range (mm/kasan/generic.c:186 mm/kasan/generic.c:200) __asan_memset (mm/kasan/shadow.c:84) usb6fire_pcm_in_urb_handler (sound/usb/6fire/pcm.c:338) __usb_hcd_giveback_urb (drivers/usb/core/hcd.c:1657) usb_hcd_giveback_urb (drivers/usb/core/hcd.c:1741) vhci_rx_loop (drivers/usb/usbip/vhci_rx.c:107 drivers/usb/usbip/vhci_rx.c:242) kthread (kernel/kthread.c:436) ret_from_fork (arch/x86/kernel/process.c:158) ret_from_fork_asm (arch/x86/entry/entry_64.S:245) Allocated by task 10: __kmalloc_cache_noprof (mm/slub.c:5563) usb6fire_pcm_init (sound/usb/6fire/pcm.c:560 sound/usb/6fire/pcm.c:595) usb6fire_chip_probe (sound/usb/6fire/chip.c:133) usb_probe_interface (drivers/usb/core/driver.c:399) The buggy address belongs to the object at ffff88802a3d0000 which belongs to the cache kmalloc-8k of size 8192 The buggy address is located 0 bytes inside of 4832-byte region [ffff88802a3d0000, ffff88802a3d12e0) Kernel panic - not syncing: Fatal exception in interrupt
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux c6d43ba816d1cf1d125bfbfc938f2a28a87facf9 ~ 61e665fb48e9eee44ec6d610514af383b1802cc1 -
Linux Linux 2.6.39 -

II. Public POCs for CVE-2026-98312

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-98312

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-98312 (5)

Same Patch Batch · Linux · 2026-10-06 · 208 CVEs total

CVE-2026-98323 9.8 CRITICAL RDMA/siw: Bound fragmented header copies by the remaining length
CVE-2026-98365 9.8 CRITICAL RDMA/rxe: Fix integer overflow in mr_check_range() leading to OOB access
CVE-2026-98282 8.8 HIGH powerpc/iommu: Fix the overflow validation in iommu_tce_check_ioba
CVE-2026-98283 8.8 HIGH KVM: PPC: Book3S HV: fix use-after-free in kvmhv_emulate_tlbie_all_lpid()
CVE-2026-98339 8.8 HIGH wifi: cfg80211: don't filter by BSS type when removing stale entries
CVE-2026-98171 8.8 HIGH smb: client: fix next_buffer UAF and NextCommand bounds in compound PDUs
CVE-2026-98261 8.1 HIGH cifs: Fix server use-after-free in cifs_chan_skip_or_disable()
CVE-2026-98357 8.1 HIGH IB/isert: wait for deferred control PDU completions before releasing the connection
CVE-2026-98239 8.1 HIGH net: lan743x: fix RX checksum use-after-free
CVE-2026-98305 7.8 HIGH net: dsa: mxl862xx: disable the stats poll on teardown
CVE-2026-98341 7.8 HIGH wifi: cfg80211: don't free driver-owned scan requests
CVE-2026-98320 7.8 HIGH netfilter: flowtable: hold reference on ct until flow is released
CVE-2026-98228 7.8 HIGH mips: select CONFIG_WEAK_REORDERING_BEYOND_LLSC from CONFIG_EYEQ
CVE-2026-98229 7.8 HIGH xfrm: save input state data before secpath resets
CVE-2026-98318 7.8 HIGH smb: client: validate absolute native symlink targets before NT fixups
CVE-2026-98315 7.8 HIGH ntfs: protect runlist updates with the runlist lock
CVE-2026-98311 7.8 HIGH wifi: virt_wifi: don't transfer operstate before register
CVE-2026-98276 7.8 HIGH net: lock the socket in sock_gettstamp()
CVE-2026-98258 7.8 HIGH posix-cpu-timers: Prevent freeing a timer which is queued on the expiry list
CVE-2026-98260 7.8 HIGH exec: Cleanup POSIX timers right after de_thread()

Showing top 20 of 208 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-98312

No comments yet


Leave a comment