Skip to main content
Vulnerability Database/CVE-2026-80815

CVE-2026-80815: Linux Kernel ALSA Scarlett2 Buffer Overflow

CVE-2026-80815 is a buffer overflow flaw in the Linux Kernel ALSA Scarlett2 driver that could lead to system crashes and unauthorized code execution. This article covers the technical details, affected versions, and mitigation.

Published:

CVE-2026-80815 Overview

CVE-2026-80815 is a Linux kernel vulnerability in the ALSA scarlett2 USB audio driver. The driver reused the shared mixer->urb allocated by snd_usb_mixer_status_create() for the UAC2 status interrupt endpoint. On devices exposing that endpoint, the "already in use" check triggers and scarlett2_init_notify() returns success without submitting the notification URB or initializing the cmd_done completion. A subsequent scarlett2_usb_init() call then reaches wait_for_completion_timeout() against a zeroed wait.head, producing a kernel crash.

Critical Impact

A local user with access to a Focusrite Scarlett USB audio interface can trigger a kernel crash through the uninitialized completion structure, resulting in denial of service.

Affected Products

  • Linux kernel ALSA subsystem — sound/usb/mixer_scarlett2.c driver
  • Focusrite Scarlett USB audio interface support paths using UAC2 status interrupt endpoints
  • Distributions shipping affected upstream kernel versions prior to the referenced stable fixes

Discovery Timeline

  • 2026-09-04 - CVE-2026-80815 published to NVD
  • 2026-09-04 - Last updated in NVD database

Technical Details for CVE-2026-80815

Vulnerability Analysis

The defect stems from URB (USB Request Block) ownership confusion between the generic ALSA USB mixer code and the vendor-specific scarlett2 driver. scarlett2_init_notify() attempted to submit a notification URB using mixer->urb, a resource that mixer.c already allocates and manages for the UAC2 status interrupt endpoint.

When the device exposes the UAC2 status endpoint, usb_submit_urb() detects the URB is already active. The function silently returns 0, skipping notification setup entirely. The cmd_done completion object is never initialized because its setup lives past the failing check.

Subsequent execution of scarlett2_usb_init() issues the SCARLETT2_USB_INIT_1 command and calls wait_for_completion_timeout() on the uninitialized completion. The kernel then dereferences a zeroed wait.head list, causing a crash [CWE-908: Use of Uninitialized Resource].

Root Cause

The root cause is shared ownership of a single URB structure between two subsystems with incompatible lifecycle assumptions. mixer.c freed the URB in snd_usb_mixer_free() and resubmitted it in snd_usb_mixer_activate(), while scarlett2 assumed exclusive use. The cmd_done completion was initialized only on a code path that could be skipped, leaving stale zeroed memory reachable by the wait primitive.

Attack Vector

Exploitation requires local access with the ability to attach or interact with a Focusrite Scarlett USB device that exposes the UAC2 status interrupt endpoint. Loading the driver against such a device triggers the crash path during initialization. The fix introduces a private URB in scarlett2_data, moves cmd_done initialization into scarlett2_init_private(), and adds scarlett2_cleanup_urb() plus a private_resume callback to correctly re-establish the URB after suspend. reinit_completion() clears stale completion state before subsequent commands.

See the upstream fixes referenced in the kernel stable tree commit 013448eb and related backports for technical details.

Detection Methods for CVE-2026-80815

Indicators of Compromise

  • Kernel oops or panic traces referencing wait_for_completion_timeout, scarlett2_usb_init, or scarlett2_init_notify in dmesg output
  • Unexpected reboots or system hangs coinciding with connection of Focusrite Scarlett USB audio interfaces
  • snd_usb_audio module logs showing repeated URB submission errors for the mixer status endpoint

Detection Strategies

  • Inventory Linux endpoints running kernel versions predating the fix commits and cross-reference against Focusrite Scarlett USB device presence via lsusb telemetry
  • Monitor kernel ring buffer and journalctl -k for stack traces mentioning scarlett2 symbols
  • Correlate USB device attach events with subsequent kernel instability using host telemetry pipelines

Monitoring Recommendations

  • Forward kernel logs to centralized logging for pattern matching on scarlett2_ function names in panic traces
  • Track kernel package versions across the fleet and alert on hosts running unpatched builds with USB audio hardware attached
  • Enable crash-dump collection so post-mortem analysis can confirm the uninitialized-completion signature

How to Mitigate CVE-2026-80815

Immediate Actions Required

  • Update to a Linux kernel version containing the upstream fixes referenced in the NVD advisory
  • Restrict physical and administrative access to systems where Focusrite Scarlett USB devices are used until patches are applied
  • Blacklist the snd_usb_audio module on systems that do not require USB audio functionality as a temporary control

Patch Information

The upstream fix replaces the shared mixer->urb with a private URB stored in scarlett2_data, initializes cmd_done in scarlett2_init_private(), and adds proper cleanup and resume callbacks. Apply patches from the stable kernel tree: commit 013448eb, commit 04df0232, commit 4305e4b5, commit cd17d6ff, and commit ecd2f83a.

Workarounds

  • Unload or blacklist the snd_usb_audio kernel module on hosts that do not require USB audio
  • Physically disconnect affected Focusrite Scarlett USB devices from vulnerable Linux systems until the kernel is patched
  • Disable USB port access via udev rules or BIOS controls on systems where USB audio is not required
bash
# Blacklist snd_usb_audio until patched kernel is deployed
echo "blacklist snd_usb_audio" | sudo tee /etc/modprobe.d/blacklist-snd-usb-audio.conf
sudo modprobe -r snd_usb_audio
sudo update-initramfs -u

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.