CVE-2026-46146

Published: Mag 28, 2026 Last Modified: Mag 28, 2026
ExploitDB:
Other exploit source:
Google Dorks:

Description

AI Translation Available

In the Linux kernel, the following vulnerability has been resolved:

ALSA: usb-audio: Avoid potential endless loop in convert_chmap_v3()

The convert_chmap_v3() has a loop with its increment size of
cs_desc->wLength, but we forgot to validate cs_desc->wLength itself,
which may lead to potential endless loop by a malformed descriptor.

Add a proper size check to abort the loop for plugging the hole.

https://git.kernel.org/stable/c/4e0ee232ebe3df04874125d7c7f3e6c25ea5483d
https://git.kernel.org/stable/c/6e7247d8f5fefeceb0bb9cc80a5388a636b219cd
https://git.kernel.org/stable/c/be09b47ed8677d76962e3240c145502e2ad9f3c8
https://git.kernel.org/stable/c/e0e3dcf48189603f3865f1a0b799b3b42baae96d
https://git.kernel.org/stable/c/fa5b19ce69067874b1413f3c2027563bae8c2cb3