Tracker / CVE-2026-31620
CVE-2026-31620
Medium 4.6
In the Linux kernel, the following vulnerability has been resolved: ALSA: usx2y: us144mkii: fix NULL deref on missing interface 0 A malicious USB device with the TASCAM US-144MKII device id can have a configuration containing bInterfaceNumber=1 but no interface 0. USB configuration descriptors are not required to assign interface numbers sequentially, so usb_ifnum_to_if(dev, 0) returns will NULL, which will then be dereferenced directly. Fix this up by checking the return value properly.
Affected products and versions
| linux | linux_kernel · 6.18 → 6.18.24 |
|---|---|
| linux | linux_kernel · 6.19 → 6.19.14 |
| linux | linux_kernel · 7.0 → 7.0.1 |
Analysis
This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.