Back

MEDIUM

ALSA: usb-audio: Fix potential memory leaks

Published Oct 4, 2025

Description

When the driver hits -ENOMEM at allocating a URB or a buffer, it aborts and goes to the error path that releases the all previously allocated resources. However, when -ENOMEM hits at the middle of the sync EP URB allocation loop, the partially allocated URBs might be left without released, because ep->nurbs is still zero at that point.

Fix it by setting ep->nurbs at first, so that the error handler loops over the full URB list.

Affected products

Remediation

Red Hat statement

USB audio devices often use isochronous endpoints for audio streaming, with separate synchronization endpoints for clock recovery. During initialization, the driver allocates multiple URBs (USB Request Blocks) for these endpoints. The allocation happens in a loop: create URB, allocate buffer, repeat. The ep->nurbs field tracks how many URBs have been successfully allocated. Here's the problem: ep->nurbs is only set after the entire loop completes successfully. If allocation fails midway—say, the driver successfully allocates 5 URBs but fails on the 6th due to -ENOMEM—the error handler is supposed to clean up. It loops from 0 to ep->nurbs, freeing each URB. But since ep->nurbs is still zero (it was never updated), the loop doesn't execute at all. The 5 successfully allocated URBs are simply abandoned. Each time USB audio initialization fails under memory pressure, more URBs leak. The fix is simple: set ep->nurbs before starting the loop, so the cleanup knows how far to iterate.

Weaknesses (2)

References (15)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Linux
Published Oct 4, 2025
Updated May 11, 2026
Reserved Oct 4, 2025
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Oct 4, 2025
ENISA EUVD
Assigner Linux
Published Oct 4, 2025
Updated May 11, 2026
Exploited since n/a
EUVD-2025-32370