CVE-2026-43436
In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Check endpoint numbers at parsing Scarlett2 mixer interfaces The Scarlett2 mixer quirk in USB-audio driver may hit a NULL dereference when a malformed USB descriptor is passed, since it assumes the presence of an endpoint in the parsed interface in scarlett2_find_fc_interface(), as reported by fuzzer. For avoiding the NULL dereference, just add the sanity check of bNumEndpoints and skip the invalid interface.
Debilidad
In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Check endpoint numbers at parsing Scarlett2 mixer interfaces The Scarlett2 mixer quirk in USB-audio driver may hit a NULL dereference when a malformed USB descriptor is passed, since it assumes the presence of an endpoint in the parsed interface in scarlett2_find_fc_interface(), as reported by fuzzer. For avoiding the NULL dereference, just add the sanity check of bNumEndpoints and skip the invalid interface.
Productos afectados
- linux linux_kernel
Referencias
- https://git.kernel.org/stable/c/3d4f23885e4b90347c9a1d779af6e79a99b5172a
- https://git.kernel.org/stable/c/3d542cf3c4c854cdf5d58049771f68926b9eb2b9
- https://git.kernel.org/stable/c/b014cc945baba75816cda0cf8934be87c9ed4947
- https://git.kernel.org/stable/c/b267255c15d2a5b90c4e926146aa155e5161e264
- https://git.kernel.org/stable/c/c5c5a6c53cf3b658f1d4512dfa61f3cd25bc34ba
- https://git.kernel.org/stable/c/df1d8abf36ca3681c21a6809eaa9a1e01ef897a6
Encuentra el fallo antes que un atacante.
Inicia sesión con GitHub y ejecuta tu primera auditoría en menos de un minuto. El plan gratuito no requiere tarjeta de crédito.