{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  ALSA: bcd2000: clear the URB pointers on disconnect  bcd2000_free_usb_related_resources() frees both URBs and leaves the pointers behind:  \tusb_kill_urb(bcd2k-\u003emidi_out_urb); \tusb_kill_urb(bcd2k-\u003emidi_in_urb);  \tusb_free_urb(bcd2k-\u003emidi_out_urb); \tusb_free_urb(bcd2k-\u003emidi_in_urb);  The rawmidi device outlives that call.  A substream that is still open when the device is unplugged reaches bcd2000_midi_send() from the trigger path on close.  That function writes to the freed URB and then hands it to the USB core:  \tbcd2k-\u003emidi_out_urb-\u003etransfer_buffer_length = BUFSIZE; \t... \tret = usb_submit_urb(bcd2k-\u003emidi_out_urb, GFP_ATOMIC);  usb_kill_urb() does not stop a later submission either, so a submit that races the disconnect can requeue the URB after it has been reaped. midi_in_urb is exposed the same way: bcd2000_input_complete() resubmits it from the completion handler.  KASAN on 7.2.0-rc5 (arm64):    BUG: KASAN: slab-use-after-free in bcd2000_midi_send [snd_bcd2000]   Write of size 4 at addr ffff00001827d388 by task bpoc/168    __asan_store4    bcd2000_midi_send [snd_bcd2000]    bcd2000_midi_output_trigger [snd_bcd2000]    snd_rawmidi_kernel_write1    close_substream.part.0   Freed by task 168:    usb_free_urb    bcd2000_disconnect [snd_bcd2000]    BUG: KASAN: slab-use-after-free in usb_submit_urb   Read of size 8 at addr ffff00001827d3b8 by task bpoc/168  Clear both pointers after freeing and test them on the paths that can still run.  Poison the URBs before freeing them: usb_poison_urb() waits for a running completion handler and rejects any later submission, so after it returns the input path is quiesced and only the rawmidi trigger path can still reach bcd2000_midi_send().  No unpoison is needed; the URBs are freed on the next line.  Discovered by XBOW, triaged by Baul Lee \u003cbaul.lee@xbow.com\u003e",
  "id": "DEBIAN-CVE-2026-80971",
  "modified": "2026-09-15T08:47:36.921631927Z",
  "published": "2026-09-11T20:19:03.233Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-80971"
    }
  ],
  "severity": [
    {
      "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "type": "CVSS_V3"
    }
  ],
  "upstream": [
    "CVE-2026-80971"
  ]
}