ALSA: caiaq: fix out-of-bounds read in the Traktor Kontrol S4 input parser
Published Jul 25, 2026
5.5
MEDIUMCVSS 3.1
EPSS 0.22%
Description
snd_usb_caiaq_tks4_dispatch() decodes the Traktor Kontrol S4 input stream in fixed 16-byte (TKS4_MSGBLOCK_SIZE) message blocks. On every iteration it advances buf and subtracts the block size while looping on "while (len)".
len is urb->actual_length. That value is supplied by the device and is not guaranteed to be a multiple of 16. When a final short block leaves len between 1 and 15, the loop runs once more, reads up to buf[15], and then does "len -= TKS4_MSGBLOCK_SIZE". As len is unsigned this underflows to a huge value. The loop then keeps iterating and walking buf far past the end of the 512-byte ep4_in_buf, reading out of bounds until a bogus block id happens to be hit.
Iterate only while a full message block is available. This stops the unsigned underflow and silently drops any trailing partial block, which carries no complete control value anyway.
The sibling endpoint-4 parsers are not affected. The Traktor Kontrol X1 and Maschine arms in snd_usb_caiaq_ep4_reply_dispatch() floor urb->actual_length before dispatching.
Affected products
-
Affected
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
-
Affected
- 2.6.37
Unaffected
- ≥ 0, < 2.6.37
- ≥ 5.10.261, ≤ 5.10.*
- ≥ 5.15.212, ≤ 5.15.*
- ≥ 6.1.178, ≤ 6.1.*
- ≥ 6.12.96, ≤ 6.12.*
- ≥ 6.18.39, ≤ 6.18.*
- ≥ 6.6.145, ≤ 6.6.*
- ≥ 7.1.4, ≤ 7.1.*
- 7.2
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Linux | Linux | unaffected | Affected
|
| Linux | Linux | affected | Affected
Unaffected
|
No data.
No data.
Red Hat Enterprise Linux 10
kernel
Fix deferred
Red Hat Enterprise Linux 6
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel
Fix deferred
Red Hat Enterprise Linux 7
kernel-rt
Fix deferred
Red Hat Enterprise Linux 8
kernel
Fix deferred
Red Hat Enterprise Linux 8
kernel-rt
Fix deferred
Red Hat Enterprise Linux 9
kernel
Fix deferred
Red Hat Enterprise Linux 9
kernel-rt
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | kernel | Fix deferred | n/a |
| Red Hat Enterprise Linux 6 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel | Fix deferred | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | kernel | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | kernel | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (14)
- https://access.redhat.com/security/cve/CVE-2026-64487 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2507086 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-48831 Advisory
- https://git.kernel.org/stable/c/05df59b9a61f7ca66548df079d306c41da23845d
- https://git.kernel.org/stable/c/0680413f2f10aab43878dd3db711a6a9e45bab7c
- https://git.kernel.org/stable/c/3cad86197c7bf8b45bb1d8adc1099d0913e80469
- https://git.kernel.org/stable/c/70d6d4cfa4ad09688aed2ec8a0cfa72c31f60334
- https://git.kernel.org/stable/c/884f575cc6acb136eb4a161d925147f85b59c27e
- https://git.kernel.org/stable/c/a5fd3122283bf75c04f6414bf610100beb0565b0
- https://git.kernel.org/stable/c/de5f9edc705497b1b2c6b173b22f283486d2fd91
- https://git.kernel.org/stable/c/f7f3f9fd81e7adbaa12c2e62ee07f0e094a543fd
- https://lore.kernel.org/linux-cve-announce/2026072549-CVE-2026-64487-03f3@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2026-64487
- https://www.cve.org/CVERecord?id=CVE-2026-64487
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
GitHub
No data