PT-2026-37619 · Linux · Linux Kernel

Published

2026-05-06

·

Updated

2026-05-07

·

CVE-2026-43279

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the ALSA usb-audio component where the system blindly assumes received packets fit the buffer size when silencing playback URB (USB Request Block) packets in implicit fb mode. If the capture stream setup differs from the playback stream, such as due to USB core max packet size limitations, it can lead to out-of-bounds (OOB) writes to the buffer, resulting in a kernel crash.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Memory Corruption

Weakness Enumeration

Related Identifiers

CVE-2026-43279

Affected Products

Linux Kernel