← All Advisories

CVE-2026-97930

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-97930

Key Details

CVECVE-2026-97930
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

ALSA: usbusx2y: fix in04_last array size mismatch with in04_buf

The in04_last array in struct usx2ydev is declared as char[24], but

in04_buf is allocated as sizeof(struct us428_ctls) which is 21 bytes.

In i_usx2y_in04_int(), when ctl_snapshot_last == -2 (initialization

path):

memcpy(usx2y->in04_last, usx2y->in04_buf, sizeof(usx2y->in04_last));

This copies 24 bytes from a 21-byte slab allocation, reading 3 bytes

past the end of the source object.

Introduce a USX2Y_IN04_SIZE constant defined as sizeof(struct

us428_ctls) and use it consistently for the in04_last array, the

in04_buf allocation, the URB transfer length, and the comparison loop,

replacing the bare 24 and 21 literals throughout. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-97930
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-97930