SB20260912400 - Out-of-bounds read in Linux kernel usb 6fire



SB20260912400 - Out-of-bounds read in Linux kernel usb 6fire

Published: September 12, 2026

Security Bulletin ID SB20260912400
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Physical access
Highest impact Information disclosure

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Out-of-bounds read (CVE-ID: CVE-2026-80973)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 5.1 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows an attacker with physical access to disclose kernel memory.

The vulnerability exists due to an out-of-bounds read in usb6fire_comm_receiver_handler() when processing MIDI events from a connected USB device. An attacker with physical access can provide a MIDI event with an excessive length value to disclose kernel memory.

The receiver is submitted during device probing, and forwarding data through the rawmidi read path requires an open MIDI input substream.


Remediation

Install update from vendor's website.