Out-of-bounds write in Linux kernel - CVE-2026-80829
Published: September 5, 2026
Vulnerability details
The vulnerability allows an attacker with physical access to cause memory corruption.
The vulnerability exists due to an out-of-bounds write in snd_usbmidi_novation_output() when handling USB MIDI output from a device with an undersized bulk OUT endpoint. An attacker with physical access can connect a malicious USB device that advertises a one-byte bulk OUT endpoint to cause memory corruption.
Affected software
How to mitigate CVE-2026-80829
External References
- https://git.kernel.org/stable/c/1035a8f63bae28e498b0e7b5ac91d749844a7158
- https://git.kernel.org/stable/c/1074c2306901b44ebcb83855583c6776e1e392ea
- https://git.kernel.org/stable/c/558fc4485ecc704edfe7876d6cebae4738ff7ef8
- https://git.kernel.org/stable/c/7639ec9755d3ec0ec8cd7c0fdd2c3d3997434870
- https://git.kernel.org/stable/c/7f00dbddb51f4f74325cdc7c3f6b19fb3392481a
- https://git.kernel.org/stable/c/91919b3b99ab7ce3d7dbb39fcf7c6c742a663c0c
- https://git.kernel.org/stable/c/94e4562fcc81badd1d467ddfb88c27e4fae974c2
- https://git.kernel.org/stable/c/9c8212436631b0063cb021e9f58df438e3db84d0
- https://git.kernel.org/stable/c/e9c00d7533f99aa9833c4b598f47e3b3202fdb9a