PT-2026-37619 · Linux+1 · Linux Kernel+1

CVE-2026-43279

·

Published

2026-05-06

·

Updated

2026-07-13

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the ALSA usb-audio component where the system blindly assumes received packets fit the buffer size when silencing playback URB (USB Request Block) packets in implicit fb mode. If the capture stream setup differs from the playback stream, such as due to USB core max packet size limitations, it can lead to out-of-bounds (OOB) writes to the buffer, resulting in a kernel crash.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:27353
ALSA-2026:27354
ALSA-2026:27789
ALSA-2026:33685
CVE-2026-43279
RHSA-2026:33685
RHSA-2026:33900
RHSA-2026:34095
SUSE-SU-2026:2914-1
USN-8492-1
USN-8492-2
USN-8492-3
USN-8492-4
USN-8492-5
USN-8497-1
USN-8498-1
USN-8499-1

Affected Products

Linux Kernel
Rocky Linux