CVE-2026-74641
Gravedad:
Pendiente de análisis
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
22/08/2026
Última modificación:
23/08/2026
Descripción
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
ALSA: usx2y: bound the hwdep mmap fault offset<br />
<br />
snd_us428ctls_vm_fault() turns the faulting page offset into a kernel<br />
address with no bound of any kind:<br />
<br />
offset = vmf->pgoff page = page;<br />
<br />
return 0;<br />
<br />
snd_us428ctls_mmap() checks only the length of the mapping, never the<br />
offset, and us428ctls_sharedmem is a single page from<br />
alloc_pages_exact(). For a character device file_mmap_size_max()<br />
returns ULONG_MAX, so the mm layer imposes no ceiling either. Every page<br />
offset above zero resolves to a struct page outside the object, and the<br />
handler installs it into the caller&#39;s address space read-write; the vma<br />
is not marked read-only.<br />
<br />
The caller picks the page frame with a single mmap() argument and gets<br />
read-write access to a page of kernel memory it does not own; an offset<br />
that lands in an unpopulated vmemmap region oopses instead.<br />
<br />
A process that can open the hwdep node of an attached US-X2Y reaches<br />
this after loading the FPGA image through the same node; no capability<br />
check is involved.<br />
<br />
On 7.2.0-rc5 (arm64), mmap() with a large offset:<br />
<br />
Unable to handle kernel paging request at virtual address fffffdffc45d5ac8<br />
pc : snd_us428ctls_vm_fault+0x68/0x140 [snd_usb_usx2y]<br />
Call trace:<br />
snd_us428ctls_vm_fault+0x68/0x140 [snd_usb_usx2y]<br />
__do_fault<br />
__handle_mm_fault<br />
handle_mm_fault<br />
el0_da<br />
<br />
Reject any offset outside the shared region. The pcm hwdep handler in<br />
usx2yhwdeppcm.c computes its address the same way and needs the same<br />
bound.<br />
<br />
Discovered by XBOW, triaged by Baul Lee
Impacto
Referencias a soluciones, herramientas e información
- https://git.kernel.org/stable/c/10a87401fb3148c388e55df0148295b3b137da07
- https://git.kernel.org/stable/c/2ca1eea3cd17930daffe9e429a7c89232036ec24
- https://git.kernel.org/stable/c/34ab56ed854baa73a731cfd99af689f0b1bac444
- https://git.kernel.org/stable/c/4208db2453e1ea71b8048a5b7802360cb29a53f1
- https://git.kernel.org/stable/c/5bf5ccddf00b59f1e3ea7e65d76a5f5b5c21cc2e
- https://git.kernel.org/stable/c/ad6fedea65c6e90eda00d716c8bf20cdc437ed10
- https://git.kernel.org/stable/c/f613b4a2d87247b51a1b2b330f2e083a454125f2
- https://git.kernel.org/stable/c/f75d6f61f0d9c5c1ea725104014e10d26d1e3a00


