SB2026092566 - Out-of-bounds read in Linux kernel usb caiaq



SB2026092566 - Out-of-bounds read in Linux kernel usb caiaq

Published: September 25, 2026

Security Bulletin ID SB2026092566
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Physical access
Highest impact Information disclosure

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Out-of-bounds read (CVE-ID: CVE-2026-93808)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 0 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows an attacker with physical access to cause an out-of-bounds read.

The vulnerability exists due to improper length validation in the ALSA USB CAIAQ EP1 reply handling code when processing undersized EP1 replies. An attacker with physical access can provide a malformed EP1 reply to cause an out-of-bounds read.


Remediation

Install update from vendor's website.