Sploitus

CVE-2026-74497

No indexed exploits for CVE-2026-74497 yet

In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Clamp frame size in implicit-feedback mode snd_usb_handle_sync_urb() scales received sync packet sizes by the sender's stride and stores the result directly in out_packet->packet_size[i]. If a connected USB device sends an oversized sync packet, this frame count can exceed ep->maxframesize. The un-clamped frame count then propagates to the playback endpoint queue, potentially driving packet transfers beyond the endpoint's hardware frame limits. Cap the calculated frame count against ep->maxframesize in snd_usb_handle_sync_urb() to prevent oversized packets from entering the playback queue.

Affected products
Linux Kernel
CVSS 3.1
8.4 HIGH
EPSS
0.1% (4th percentile)
NVD status
Received
Published
2026-08-15
CVE-2026-74497 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2026-74497 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2026-74497 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.