SB2026091678 - Out-of-bounds write in Linux kernel usb
Published: September 16, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Out-of-bounds write (CVE-ID: CVE-2026-90033)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 5.1 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows an attacker with physical access to cause a denial of service.
The vulnerability exists due to an out-of-bounds write in snd_usbmidi_us122l_output() when processing MIDI output for a USB device that declares a bulk endpoint smaller than the expected transfer count. An attacker with physical access can connect a crafted USB device to cause a denial of service.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/1d4add2b832b56f81bb0eab065ec35c610343018
- https://git.kernel.org/stable/c/2dae0e3a59e31f78222279d544b98e747cd1fbff
- https://git.kernel.org/stable/c/5538daf2a5cc80ac3f3e913c0db045d92d995d40
- https://git.kernel.org/stable/c/9392a2c346762ffee8edd1ba8bac50d2e24a2ed7
- https://git.kernel.org/stable/c/9d81885d97cba7796d1f8edc88f2499c8296f5b9
- https://git.kernel.org/stable/c/a441a8e52148c91c2f2a91f42e3b9bc961a13a4b
- https://git.kernel.org/stable/c/de6d252f115be887a701c09a05cdb076f3a590c9
- https://git.kernel.org/stable/c/e4637ce34607f1733a34a57294966d26b263e626