← Back

CVE-2026-46146

nvd nist
Published: May 28, 2026Modified: Jun 10, 2026

JSON object

Loading...
5.5
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Exploitability: 1.8 / Impact: 3.6
Source: NVD

Description

In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Avoid potential endless loop in convert_chmap_v3() The convert_chmap_v3() has a loop with its increment size of cs_desc->wLength, but we forgot to validate cs_desc->wLength itself, which may lead to potential endless loop by a malformed descriptor. Add a proper size check to abort the loop for plugging the hole.

Affected (18)

Products: Linux: Linux Kernel
1 product
Linux Kernel
Configuration A
18 vulnerable
Vulnerable SoftwareAffected Versions
Linux
From 5.10.241 to 5.10.258
From 5.15.190 to 5.15.209
From 5.4.297 to 5.5
From 6.1.149 to 6.1.175
From 6.12.43 to 6.12.88
From 6.15.11 to 6.16
From 6.16.2 to 6.17
From 6.17.1 to 6.18.30
From 6.19 to 7.0.7
From 6.6.103 to 6.6.140
Version 6.17
Version 6.17 rc2
Version 6.17 rc3
Version 6.17 rc4
Version 6.17 rc5
Version 6.17 rc6
Version 6.17 rc7
Version 7.1 rc1

References (8)

Source: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Patch
Source: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Patch
Source: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Patch
Source: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Patch
Source: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Patch
Source: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Patch
Source: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Patch
Source: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Patch

Timeline

No history available yet.