SB20260325137 - Out-of-bounds read in Linux kernel usb
Published: March 25, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Out-of-bounds read (CVE-ID: CVE-2026-23318)
The vulnerability allows an attacker with physical access to cause a denial of service.
The vulnerability exists due to improper input validation in the ALSA usb-audio driver when handling USB audio descriptors from a UAC3 device. An attacker with physical access can connect a malicious USB device presenting a truncated UAC3 header to cause out-of-bounds reads, leading to a denial of service.
Exploitation requires physical access to attach a malicious USB device.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/0dcd1ed96c03459cf14706885c9dd3c1fd8bd29f
- https://git.kernel.org/stable/c/1e5753ff4c2e86aa88516f97a224c90a3d0b133e
- https://git.kernel.org/stable/c/499ffd15b00dc91ac95c28f76959dfb5cdcc84d5
- https://git.kernel.org/stable/c/54f9d645a5453d0bfece0c465d34aaf072ea99fa
- https://git.kernel.org/stable/c/a0c6ae2ea84528f198bf7fd0117f12fd0cf6d7cc
- https://git.kernel.org/stable/c/d3904ca40515272681ae61ad6f561c24f190957f