Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-64487

Gravedad:
Pendiente de análisis
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
25/07/2026
Última modificación:
25/07/2026

Descripción

*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> ALSA: caiaq: fix out-of-bounds read in the Traktor Kontrol S4 input parser<br /> <br /> snd_usb_caiaq_tks4_dispatch() decodes the Traktor Kontrol S4 input<br /> stream in fixed 16-byte (TKS4_MSGBLOCK_SIZE) message blocks. On every<br /> iteration it advances buf and subtracts the block size while looping on<br /> "while (len)".<br /> <br /> len is urb-&gt;actual_length. That value is supplied by the device and is<br /> not guaranteed to be a multiple of 16. When a final short block leaves<br /> len between 1 and 15, the loop runs once more, reads up to buf[15], and<br /> then does "len -= TKS4_MSGBLOCK_SIZE". As len is unsigned this underflows<br /> to a huge value. The loop then keeps iterating and walking buf far past<br /> the end of the 512-byte ep4_in_buf, reading out of bounds until a bogus<br /> block id happens to be hit.<br /> <br /> Iterate only while a full message block is available. This stops the<br /> unsigned underflow and silently drops any trailing partial block, which<br /> carries no complete control value anyway.<br /> <br /> The sibling endpoint-4 parsers are not affected. The Traktor Kontrol X1<br /> and Maschine arms in snd_usb_caiaq_ep4_reply_dispatch() floor<br /> urb-&gt;actual_length before dispatching.

Impacto