CVE-2026-80829
Last modified
CVE-2026-80829 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: fix OOB write in snd_usbmidi_novation_output() snd_usbmidi_novation_output() lays out a two-byte header at transfer_buffer[0..1] and passes &transfer_buffer[2] together with a length of ep->max_transfer - 2 to snd_rawmidi_transmit(): count = snd_rawmidi_transmit(ep->ports[0].substream, &transfer_buffer[2], ep->max_transfer - 2); ep->max_transfer comes from the output endpoint's wMaxPacketSize via usb_maxpacket(). A malformed or malicious device can advertise a bulk OUT endpoint with a wMaxPacketSize of 1 - the USB core only clamps this value downwards - so ep->max_transfer becomes 1 and the count argument becomes -1. snd_rawmidi_transmit() passes the negative count on to __snd_rawmidi_transmit_peek(), where "if (count1 > count) count1 = count" leaves count1 negative; get_aligned_size() keeps it negative for a byte-stream substream, so the following memcpy(buffer, ..., count1) runs with a (size_t)-1 length and writes far past the transfer buffer, which was allocated with usb_alloc_coherent(ep->max_transfer). This is the same class of bug that was fixed for snd_usbmidi_akai_output() in commit 0970274613fb ("ALSA: usb-audio: fix OOB write in snd_usbmidi_akai_output()"); the novation output routine was left unguarded.
Description
In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: fix OOB write in snd_usbmidi_novation_output() snd_usbmidi_novation_output() lays out a two-byte header at transfer_buffer[0..1] and passes &transfer_buffer[2] together with a length of ep->max_transfer - 2 to snd_rawmidi_transmit(): count = snd_rawmidi_transmit(ep->ports[0].substream, &transfer_buffer[2], ep->max_transfer - 2); ep->max_transfer comes from the output endpoint's wMaxPacketSize via usb_maxpacket(). A malformed or malicious device can advertise a bulk OUT endpoint with a wMaxPacketSize of 1 - the USB core only clamps this value downwards - so ep->max_transfer becomes 1 and the count argument becomes -1. snd_rawmidi_transmit() passes the negative count on to __snd_rawmidi_transmit_peek(), where "if (count1 > count) count1 = count" leaves count1 negative; get_aligned_size() keeps it negative for a byte-stream substream, so the following memcpy(buffer, ..., count1) runs with a (size_t)-1 length and writes far past the transfer buffer, which was allocated with usb_alloc_coherent(ep->max_transfer). This is the same class of bug that was fixed for snd_usbmidi_akai_output() in commit 0970274613fb ("ALSA: usb-audio: fix OOB write in snd_usbmidi_akai_output()"); the novation output routine was left unguarded. Bail out when the endpoint cannot hold the two-byte header plus at least one payload byte.
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2, < 558fc4485ecc704edfe7876d6cebae4738ff7ef8; >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2, < 9c8212436631b0063cb021e9f58df438e3db84d0; >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2, < e9c00d7533f99aa9833c4b598f47e3b3202fdb9a; >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2, < 94e4562fcc81badd1d467ddfb88c27e4fae974c2; >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2, < 7639ec9755d3ec0ec8cd7c0fdd2c3d3997434870; >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2, < 91919b3b99ab7ce3d7dbb39fcf7c6c742a663c0c; >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2, < 7f00dbddb51f4f74325cdc7c3f6b19fb3392481a; >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2, < 1074c2306901b44ebcb83855583c6776e1e392ea; >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2, < 1035a8f63bae28e498b0e7b5ac91d749844a7158 |
| Linux | Linux | 2.6.12 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-80829?
How severe is CVE-2026-80829?
How do I fix CVE-2026-80829?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-80823In the Linux kernel, the following vulnerability has been re…
- CVE-2026-80824In the Linux kernel, the following vulnerability has been re…
- CVE-2026-80825In the Linux kernel, the following vulnerability has been re…
- CVE-2026-80826In the Linux kernel, the following vulnerability has been re…
- CVE-2026-80827In the Linux kernel, the following vulnerability has been re…
- CVE-2026-80828In the Linux kernel, the following vulnerability has been re…
- CVE-2026-8083A vulnerability was found in SourceCodester Pharmacy Sales a…7.3
- CVE-2026-80830In the Linux kernel, the following vulnerability has been re…
- CVE-2026-80831In the Linux kernel, the following vulnerability has been re…
- CVE-2026-80832In the Linux kernel, the following vulnerability has been re…
- CVE-2026-80833In the Linux kernel, the following vulnerability has been re…
- CVE-2026-80834In the Linux kernel, the following vulnerability has been re…
Are you affected by CVE-2026-80829?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
