cbcvebase.
CVE-2026-23078
published 2026-02-04

CVE-2026-23078: In the Linux kernel, the following vulnerability has been resolved: ALSA: scarlett2: Fix buffer overflow in config retrieval The scarlett2_usb_get_config()…

PriorityP341high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.14%
4.1th percentile
In the Linux kernel, the following vulnerability has been resolved: ALSA: scarlett2: Fix buffer overflow in config retrieval The scarlett2_usb_get_config() function has a logic error in the endianness conversion code that can cause buffer overflows when count > 1. The code checks `if (size == 2)` where `size` is the total buffer size in bytes, then loops `count` times treating each element as u16 (2 bytes). This causes the loop to access `count * 2` bytes when the buffer only has `size` bytes allocated. Fix by checking the element size (config_item->size) instead of the total buffer size. This ensures the endianness conversion matches the actual element type.

Affected

59 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
debianlinux-6.1< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
linuxlinux
linuxlinux>= ac34df733d2dfe3b553897a1e9e1a44414f09834 < d5e80d1f97ae55bcea1426f551e4419245b41b9cd5e80d1f97ae55bcea1426f551e4419245b41b9c
linuxlinux>= ac34df733d2dfe3b553897a1e9e1a44414f09834 < 51049f6e3f05d70660e2458ad3bb302a3721b75151049f6e3f05d70660e2458ad3bb302a3721b751
linuxlinux>= ac34df733d2dfe3b553897a1e9e1a44414f09834 < 91a756d22f0482eac5bedb113c8922f90b25444991a756d22f0482eac5bedb113c8922f90b254449
linuxlinux>= ac34df733d2dfe3b553897a1e9e1a44414f09834 < 27049f50be9f5ae3a62d272128ce0b381cb26a2427049f50be9f5ae3a62d272128ce0b381cb26a24
linuxlinux>= ac34df733d2dfe3b553897a1e9e1a44414f09834 < 31a3eba5c265a763260976674a22851e83128f6d31a3eba5c265a763260976674a22851e83128f6d
linuxlinux>= ac34df733d2dfe3b553897a1e9e1a44414f09834 < 6f5c69f72e50d51be3a8c028ae7eda42c82902cb6f5c69f72e50d51be3a8c028ae7eda42c82902cb
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.162-16.1.162-1
linuxlinux_kernel>= 0 < 6.12.69-16.12.69-1
linuxlinux_kernel>= 0 < 6.18.8-16.18.8-1
linuxlinux_kernel>= 5.14 < 5.15.1995.15.199
linuxlinux_kernel>= 5.16 < 6.1.1626.1.162
linuxlinux_kernel>= 6.13 < 6.18.86.18.8
linuxlinux_kernel>= 6.2 < 6.6.1226.6.122
linuxlinux_kernel>= 6.7 < 6.12.686.12.68
ubuntulinux
ubuntulinux-aws
ubuntulinux-aws-fips
ubuntulinux-azure
ubuntulinux-azure-5.15
ubuntulinux-azure-6.17
ubuntulinux-azure-6.8

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.