Unrated severityNVD Advisory· Published May 8, 2026· Updated May 12, 2026
CVE-2026-43436
CVE-2026-43436
Description
In the Linux kernel, the following vulnerability has been resolved:
ALSA: usb-audio: Check endpoint numbers at parsing Scarlett2 mixer interfaces
The Scarlett2 mixer quirk in USB-audio driver may hit a NULL dereference when a malformed USB descriptor is passed, since it assumes the presence of an endpoint in the parsed interface in scarlett2_find_fc_interface(), as reported by fuzzer.
For avoiding the NULL dereference, just add the sanity check of bNumEndpoints and skip the invalid interface.
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- git.kernel.org/stable/c/3d4f23885e4b90347c9a1d779af6e79a99b5172anvd
- git.kernel.org/stable/c/3d542cf3c4c854cdf5d58049771f68926b9eb2b9nvd
- git.kernel.org/stable/c/b014cc945baba75816cda0cf8934be87c9ed4947nvd
- git.kernel.org/stable/c/b267255c15d2a5b90c4e926146aa155e5161e264nvd
- git.kernel.org/stable/c/c5c5a6c53cf3b658f1d4512dfa61f3cd25bc34banvd
- git.kernel.org/stable/c/df1d8abf36ca3681c21a6809eaa9a1e01ef897a6nvd
News mentions
0No linked articles in our index yet.