In the Linux kernel, the following vulnerability has been resolved:
ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on each resubmission
In capture_urb_complete(), usb_anchor_urb() is called on every
completion callback, but the URB is already anchored from the
initial submission in tascam_trigger_start(). Each redundant call
corrupts the anchor's doubly-linked list and inflates the URB
refcount. When usb_kill_anchored_urbs() traverses the list during
stream stop / suspend / disconnect, the corrupted list leads to
use-after-free.
Remove the redundant usb_anchor_urb() from the resubmit path.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-06 08:16
Updated : 2026-08-17 05:18
NVD link : CVE-2026-64601
Mitre link : CVE-2026-64601
CVE.ORG link : CVE-2026-64601
JSON object : View
Products Affected
No product.
CWE
No CWE.
