CVE-2026-74497 | In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Clamp frame size in implicit-feedback mode snd_usb_handle_sync_urb() scales received sync packet sizes by the sender's stride and stores the result directly in out_packet->packet_size[i]. If a connected USB device sends an oversized sync packet, this frame count can exceed ep->maxframesize. The un-clamped frame count then propagates to the playback endpoint queue, potentia
In the Linux kernel, the following vulnerability has been resolved:
ALSA: usb-audio: Clamp frame size in implicit-feedback mode
snd_usb_handle_sync_urb() scales received sync packet sizes by the sender's
stride and stores the result directly in out_packet->packet_size[i]. If a
connected USB device sends an oversized sync packet, this frame count can
exceed ep->maxframesize.
The un-clamped frame count then propagates to the playback endpoint queue,
potentially driving packet transfers beyond the endpoint's hardware frame
limits.
Cap the calculated frame count against ep->maxframesize in
snd_usb_handle_sync_urb() to prevent oversized packets from entering the
playback queue.
- 🔗 git.kernel.org/stable/c/2d39fea6d3c19a2f5811d123114d92e3…
- 🔗 git.kernel.org/stable/c/09cf3dbbb4256a43feb91d2f51f27451…
- 🔗 git.kernel.org/stable/c/cfa8d3e0e8b812c4db4d5241f62b6bdb…
- 🔗 git.kernel.org/stable/c/56ac3e7c90f6b45969c3fd07a98fad76…
- 🔗 git.kernel.org/stable/c/be97fea7451d758881b95af78e900dd0…
- 🔗 git.kernel.org/stable/c/2db4535d6af79276a64449201c5be5fe…
- 🔗 git.kernel.org/stable/c/53f0aa37eb945f3c983f61d12fc35eb3…
- 🔗 git.kernel.org/stable/c/8d7a30c50c2e58a6839634ed0acde144…
Zero-Day & Vulnerability Intelligence Hub
Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
| Tier | 2026-08-29 | 2026-09-02 |
|---|---|---|
| ≥90 % | 4 | 0 |
| ≥50 % | 4 | 0 |
| ≥10 % | 3 | 0 |
| <10 % | 304 | 300 |
CVE-2026-74497 | In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Clamp frame size in implicit-feedback mode snd_usb_handle_sync_urb() scales received sync packet sizes by the sender's stride and stores the result directly in out_packet->packet_size[i]. If a connected USB device sends an oversized sync packet, this frame count can exceed ep->maxframesize. The un-clamped frame count then propagates to the playback endpoint queue, potentia
In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Clamp frame size in implicit-feedback mode snd_usb_handle_sync_urb() scales received sync packet sizes by the sender's stride and stores the result direc