{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "7.2.8-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  ALSA: usb-audio: Clamp implicit feedback packet count to URB capacity  data_ep_set_params() allocates each data URB for exactly u-\u003epackets isochronous frames, so urb-\u003eiso_frame_desc[] has u-\u003epackets slots and ctx-\u003epackets is the driver's only record of that limit. For an implicit feedback sink, snd_usb_queue_pending_output_urbs() overwrites it with the sync source's packet count, which is calculated independently from the capture endpoint's parameters. When that count is larger, prepare_playback_urb() and prepare_silent_urb() can write iso_frame_desc[] past the allocation; their existing bounds limit payload bytes, not the descriptor index.  The reproducer uses a high-speed UAC2 device declaring bInterval 1 for implicit feedback capture (8 packets) and bInterval 4 for playback (1 packet). On the first capture completion after the stream starts, it accesses seven descriptors spanning 112 bytes beyond the one-packet URB:    BUG: KASAN: slab-out-of-bounds in prepare_playback_urb (sound/usb/pcm.c:1560)   Write of size 4 at addr ffff88801e696ad0 by task vhci_rx/178    prepare_playback_urb (sound/usb/pcm.c:1560)    prepare_outbound_urb (sound/usb/endpoint.c:340)    snd_usb_queue_pending_output_urbs (sound/usb/endpoint.c:501)    snd_complete_urb (sound/usb/endpoint.c:1834)    __usb_hcd_giveback_urb (drivers/usb/core/hcd.c:1657)    usb_hcd_giveback_urb (drivers/usb/core/hcd.c:1741)    vhci_rx_loop (drivers/usb/usbip/vhci_rx.c:107)    kthread (kernel/kthread.c:436)   The buggy address belongs to the object at ffff88801e696a00    which belongs to the cache kmalloc-256 of size 256   The buggy address is located 0 bytes to the right of    allocated 208-byte region [ffff88801e696a00, ffff88801e696ad0)  Record the allocated packet count per endpoint and clamp both the adopted count and the packet-size copy to it. Fold the Format Type II delimiter into urb_packs before the allocation loop so the recorded limit matches every URB.",
  "id": "DEBIAN-CVE-2026-98265",
  "modified": "2026-10-07T04:47:38.619986287Z",
  "published": "2026-10-06T09:18:15.797Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-98265"
    }
  ],
  "upstream": [
    "CVE-2026-98265"
  ]
}