cbcvebase.
CVE-2026-23318
published 2026-03-25

CVE-2026-23318: In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Use correct version for UAC3 header validation The entry of the validators…

PriorityP431high7.1CVSS 3.1
AVLACLPRLUINSUCHINAH
EPSS
0.13%
3.2th percentile
In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Use correct version for UAC3 header validation The entry of the validators table for UAC3 AC header descriptor is defined with the wrong protocol version UAC_VERSION_2, while it should have been UAC_VERSION_3. This results in the validator never matching for actual UAC3 devices (protocol == UAC_VERSION_3), causing their header descriptors to bypass validation entirely. A malicious USB device presenting a truncated UAC3 header could exploit this to cause out-of-bounds reads when the driver later accesses unvalidated descriptor fields. The bug was introduced in the same commit as the recently fixed UAC3 feature unit sub-type typo, and appears to be from the same copy-paste error when the UAC3 section was created from the UAC2 section.

Affected

69 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.19.8-1 (forky)linux 6.19.8-1 (forky)
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 4.19.84 < 4.204.20
linuxlinux>= 5.3.11 < 5.45.4
linuxlinux>= 57f8770620e9b51c61089751f0b5ad3dbe376ff2 < 82a7d0a1b88798de1a609130080ce0c65dd869e982a7d0a1b88798de1a609130080ce0c65dd869e9
linuxlinux>= 57f8770620e9b51c61089751f0b5ad3dbe376ff2 < 8307d93e63d5f54ef10412d4db2dd551e920dee48307d93e63d5f54ef10412d4db2dd551e920dee4
linuxlinux>= 57f8770620e9b51c61089751f0b5ad3dbe376ff2 < 0dcd1ed96c03459cf14706885c9dd3c1fd8bd29f0dcd1ed96c03459cf14706885c9dd3c1fd8bd29f
linuxlinux>= 57f8770620e9b51c61089751f0b5ad3dbe376ff2 < a0c6ae2ea84528f198bf7fd0117f12fd0cf6d7cca0c6ae2ea84528f198bf7fd0117f12fd0cf6d7cc
linuxlinux>= 57f8770620e9b51c61089751f0b5ad3dbe376ff2 < d3904ca40515272681ae61ad6f561c24f190957fd3904ca40515272681ae61ad6f561c24f190957f
linuxlinux>= 57f8770620e9b51c61089751f0b5ad3dbe376ff2 < 1e5753ff4c2e86aa88516f97a224c90a3d0b133e1e5753ff4c2e86aa88516f97a224c90a3d0b133e
linuxlinux>= 57f8770620e9b51c61089751f0b5ad3dbe376ff2 < 499ffd15b00dc91ac95c28f76959dfb5cdcc84d5499ffd15b00dc91ac95c28f76959dfb5cdcc84d5
linuxlinux>= 57f8770620e9b51c61089751f0b5ad3dbe376ff2 < 54f9d645a5453d0bfece0c465d34aaf072ea99fa54f9d645a5453d0bfece0c465d34aaf072ea99fa
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.19.8-16.19.8-1
linuxlinux_kernel>= 4.19.84 < 4.204.20
linuxlinux_kernel>= 5.11 < 5.15.2035.15.203
linuxlinux_kernel>= 5.16 < 6.1.1676.1.167
linuxlinux_kernel>= 5.3.11 < 5.45.4
linuxlinux_kernel>= 5.4.0 < 6.1.1676.1.167
linuxlinux_kernel>= 5.4.1 < 5.10.2535.10.253
linuxlinux_kernel>= 6.13 < 6.18.176.18.17
linuxlinux_kernel>= 6.13.0 < 6.18.176.18.17

CVSS provenance

nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
vendor_msrc7.7HIGH
vendor_ubuntu7.1HIGH
vendor_redhat6.6MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.