CVE-2026-46146

MEDIUM EPSS 2.8%
Published May 28, 20261mo ago · Modified Jun 17, 20261w ago
5.5 CVSS 3.1
Medium
Find Similar
Published May 28, 2026 1mo ago
Last Modified Jun 17, 2026 1w ago

Description

In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Avoid potential endless loop in convert_chmap_v3() The convert_chmap_v3() has a loop with its increment size of cs_desc->wLength, but we forgot to validate cs_desc->wLength itself, which may lead to potential endless loop by a malformed descriptor. Add a proper size check to abort the loop for plugging the hole.

CVSS Details

Base Score
5.5
Exploitability
1.8
Impact
3.6
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Attack Vector Local
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality None
Integrity None
Availability High

Threat Intelligence

EPSS Exploit Probability
2.8% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Weaknesses 1

CWE-835

Affected Products 18

VendorProductVersionRange
linuxlinux_kernel*≥5.4.297  –  <5.5
linuxlinux_kernel*≥5.10.241  –  <5.10.258
linuxlinux_kernel*≥5.15.190  –  <5.15.209
linuxlinux_kernel*≥6.1.149  –  <6.1.175
linuxlinux_kernel*≥6.6.103  –  <6.6.140
linuxlinux_kernel*≥6.12.43  –  <6.12.88
linuxlinux_kernel*≥6.15.11  –  <6.16
linuxlinux_kernel*≥6.16.2  –  <6.17
linuxlinux_kernel*≥6.17.1  –  <6.18.30
linuxlinux_kernel*≥6.19  –  <7.0.7
linuxlinux_kernel6.17any
linuxlinux_kernel6.17any
linuxlinux_kernel6.17any
linuxlinux_kernel6.17any
linuxlinux_kernel6.17any
linuxlinux_kernel6.17any
linuxlinux_kernel6.17any
linuxlinux_kernel7.1any

References 8

  • git.kernel.org https://git.kernel.org/stable/c/076d5d13eb9c1ad259a7f246149f6676c62285f9
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/24a40df79307ca7ca0eec0889361cf6ac146d72a
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/316aa0b1e3c5600eae5ab876394c1ac70e6db581
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/4e0ee232ebe3df04874125d7c7f3e6c25ea5483d
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/6e7247d8f5fefeceb0bb9cc80a5388a636b219cd
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/be09b47ed8677d76962e3240c145502e2ad9f3c8
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/e0e3dcf48189603f3865f1a0b799b3b42baae96d
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/fa5b19ce69067874b1413f3c2027563bae8c2cb3
    Patch

Remediation

  • git.kernel.org https://git.kernel.org/stable/c/076d5d13eb9c1ad259a7f246149f6676c62285f9
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/24a40df79307ca7ca0eec0889361cf6ac146d72a
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/316aa0b1e3c5600eae5ab876394c1ac70e6db581
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/4e0ee232ebe3df04874125d7c7f3e6c25ea5483d
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/6e7247d8f5fefeceb0bb9cc80a5388a636b219cd
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/be09b47ed8677d76962e3240c145502e2ad9f3c8
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/e0e3dcf48189603f3865f1a0b799b3b42baae96d
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/fa5b19ce69067874b1413f3c2027563bae8c2cb3
    Patch