CVE-2026-74502

In the Linux kernel, the following vulnerability has been resolved: ALSA: ump: fix double free of out_cvts on rawmidi error snd_ump_attach_legacy_rawmidi() allocates the legacy conversion array ump->out_cvts and, on the snd_rawmidi_new() error path, frees it with kfree() but leaves ump->out_cvts pointing at the freed memory. When the endpoint is later torn down, snd_ump_endpoint_free() frees ump->out_cvts a second time, resulting in a double free. The host snd-usb-audio driver attaches the legacy rawmidi for any USB MIDI 2.0 (UMP) device, so a device that makes snd_rawmidi_new() fail reaches this path on enumeration. Clear ump->out_cvts after freeing it on the error path so it is not freed again during teardown. Discovered by XBOW, triaged by Baul Lee <baul.lee@xbow.com>
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2026-08-15 13:17

Updated : 2026-08-17 06:19


NVD link : CVE-2026-74502

Mitre link : CVE-2026-74502

CVE.ORG link : CVE-2026-74502


JSON object : View

Products Affected

No product.

CWE

No CWE.