ALSA: bcd2000: clear the URB pointers on disconnect
Published Sep 11, 2026
7.8
HIGHCVSS 3.1
EPSS 0.16%
Description
bcd2000_free_usb_related_resources() frees both URBs and leaves the pointers behind:
usb_kill_urb(bcd2k->midi_out_urb); usb_kill_urb(bcd2k->midi_in_urb);
usb_free_urb(bcd2k->midi_out_urb); usb_free_urb(bcd2k->midi_in_urb);
The rawmidi device outlives that call. A substream that is still open when the device is unplugged reaches bcd2000_midi_send() from the trigger path on close. That function writes to the freed URB and then hands it to the USB core:
bcd2k->midi_out_urb->transfer_buffer_length = BUFSIZE; ... ret = usb_submit_urb(bcd2k->midi_out_urb, GFP_ATOMIC);
usb_kill_urb() does not stop a later submission either, so a submit that races the disconnect can requeue the URB after it has been reaped. midi_in_urb is exposed the same way: bcd2000_input_complete() resubmits it from the completion handler.
KASAN on 7.2.0-rc5 (arm64):
BUG: KASAN: slab-use-after-free in bcd2000_midi_send [snd_bcd2000] Write of size 4 at addr ffff00001827d388 by task bpoc/168 __asan_store4 bcd2000_midi_send [snd_bcd2000] bcd2000_midi_output_trigger [snd_bcd2000] snd_rawmidi_kernel_write1 close_substream.part.0 Freed by task 168: usb_free_urb bcd2000_disconnect [snd_bcd2000]
BUG: KASAN: slab-use-after-free in usb_submit_urb Read of size 8 at addr ffff00001827d3b8 by task bpoc/168
Clear both pointers after freeing and test them on the paths that can still run. Poison the URBs before freeing them: usb_poison_urb() waits for a running completion handler and rejects any later submission, so after it returns the input path is quiesced and only the rawmidi trigger path can still reach bcd2000_midi_send(). No unpoison is needed; the URBs are freed on the next line.
Discovered by XBOW, triaged by Baul Lee <baul.lee@xbow.com>
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 3.16StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<3.16
- Version 5.10.270StatusunaffectedConstraints<=5.10.*
- Version 5.15.221StatusunaffectedConstraints<=5.15.*
- Version 6.1.188StatusunaffectedConstraints<=6.1.*
- Version 6.12.109StatusunaffectedConstraints<=6.12.*
- Version 6.18.50StatusunaffectedConstraints<=6.18.*
- Version 6.6.157StatusunaffectedConstraints<=6.6.*
- Version 7.2.4StatusunaffectedConstraints<=7.2.*
- Version 7.3-rc1StatusunaffectedConstraints<=*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Linux | Linux | unaffected |
| |||||||||||||||||||||||||||||||||
| Linux | Linux | affected |
|
No data.
No data.
Red Hat Enterprise Linux 10
kernel
Affected
Red Hat Enterprise Linux 10
kernel-rt
Affected
Red Hat Enterprise Linux 6
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel
Affected
Red Hat Enterprise Linux 7
kernel-rt
Affected
Red Hat Enterprise Linux 8
kernel
Affected
Red Hat Enterprise Linux 8
kernel-rt
Affected
Red Hat Enterprise Linux 9
kernel
Affected
Red Hat Enterprise Linux 9
kernel-rt
Affected
Red Hat OpenShift Container Platform 4
openshift/ose-rhel-coreos-8
Affected
Red Hat OpenShift Container Platform 4
openshift/ose-rhel-coreos-9
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | kernel | Affected | n/a |
| Red Hat Enterprise Linux 10 | kernel-rt | Affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel | Affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-8 | Affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-9 | Affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (13)
- https://access.redhat.com/security/cve/CVE-2026-80971 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2532082 Issue Tracking
- https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2026/CVE-2026-80971.mbox
- https://git.kernel.org/stable/c/3c00004f134fc819f9d9e202c6a64acde0a1f8d0
- https://git.kernel.org/stable/c/459d3a64766f5ca2f1886daeaf24582831a5f5ab
- https://git.kernel.org/stable/c/5a77febac6faf6da40fbb4555f703eeb91b58130
- https://git.kernel.org/stable/c/6c07aad8a7c9ef8ebc4d03a964b882123a349a2e
- https://git.kernel.org/stable/c/7df3194bdb7479cad9199889655a566a2c0c1d1b
- https://git.kernel.org/stable/c/9af08677aa57debaca5b57c8045c52a83d3dd376
- https://git.kernel.org/stable/c/b06ebc7fe25a6af4a9f6e4a3d4236a4178ad4b01
- https://git.kernel.org/stable/c/eb482a06791d6168beb8c78cc904ac5a5ed96a55
- https://nvd.nist.gov/vuln/detail/CVE-2026-80971
- https://www.cve.org/CVERecord?id=CVE-2026-80971
Change history (0)
No recorded changes yet.