SB20260905127 - Out-of-bounds write in Linux kernel usb
Published: September 5, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Out-of-bounds write (CVE-ID: CVE-2026-80829)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 2.4 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows an attacker with physical access to cause memory corruption.
The vulnerability exists due to an out-of-bounds write in snd_usbmidi_novation_output() when handling USB MIDI output from a device with an undersized bulk OUT endpoint. An attacker with physical access can connect a malicious USB device that advertises a one-byte bulk OUT endpoint to cause memory corruption.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/1035a8f63bae28e498b0e7b5ac91d749844a7158
- https://git.kernel.org/stable/c/1074c2306901b44ebcb83855583c6776e1e392ea
- https://git.kernel.org/stable/c/558fc4485ecc704edfe7876d6cebae4738ff7ef8
- https://git.kernel.org/stable/c/7639ec9755d3ec0ec8cd7c0fdd2c3d3997434870
- https://git.kernel.org/stable/c/7f00dbddb51f4f74325cdc7c3f6b19fb3392481a
- https://git.kernel.org/stable/c/91919b3b99ab7ce3d7dbb39fcf7c6c742a663c0c
- https://git.kernel.org/stable/c/94e4562fcc81badd1d467ddfb88c27e4fae974c2
- https://git.kernel.org/stable/c/9c8212436631b0063cb021e9f58df438e3db84d0
- https://git.kernel.org/stable/c/e9c00d7533f99aa9833c4b598f47e3b3202fdb9a