A use-after-free vulnerability in the Linux kernel's ALSA USB-audio driver can be triggered while probing a malicious USB sound device that reports zero interfaces. In usb_audio_probe, the error path could free the card object before decrementing chip->active, leaving the driver to access a counter in freed memory. The flaw, present in code dating to around Linux kernel 3.1, may provide a local attacker with a kernel write primitive through a physically attached USB peripheral.
Commit 5f8cf712582617d523120df67d392059eaf2fc4b corrects the ordering by decrementing the active-chip counter before the card can be freed, and was designated for stable-kernel backporting. The issue was identified during fuzzing of hardware/software interfaces; researchers warned that malicious USB devices could potentially facilitate root compromise or screen-lock bypass on affected desktops and Android devices.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
Takashi Iwai committed patch 5f8cf712582617d523120df67d392059eaf2fc4b, which moves the active-chip counter decrement before a potential card-object free in sound/usb/card.c. The fix was submitted for stable-kernel backport consideration.
Hui Peng and Mathias Payer reported a use-after-free write vulnerability in the Linux kernel's USB-audio probing code, discovered while fuzzing malicious USB peripheral interactions. Exploitation required local or physical access to attach a crafted malicious USB device and could provide a kernel write primitive.
The vulnerable USB-audio error-path behavior originated with a Linux 3.1-era development change, which could free the card object before decrementing its embedded active-chip counter.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.