CVE-2026-80815 Overview
CVE-2026-80815 is a Linux kernel vulnerability in the ALSA scarlett2 USB audio driver. The driver reused the shared mixer->urb allocated by snd_usb_mixer_status_create() for the UAC2 status interrupt endpoint. On devices exposing that endpoint, the "already in use" check triggers and scarlett2_init_notify() returns success without submitting the notification URB or initializing the cmd_done completion. A subsequent scarlett2_usb_init() call then reaches wait_for_completion_timeout() against a zeroed wait.head, producing a kernel crash.
Critical Impact
A local user with access to a Focusrite Scarlett USB audio interface can trigger a kernel crash through the uninitialized completion structure, resulting in denial of service.
Affected Products
- Linux kernel ALSA subsystem — sound/usb/mixer_scarlett2.c driver
- Focusrite Scarlett USB audio interface support paths using UAC2 status interrupt endpoints
- Distributions shipping affected upstream kernel versions prior to the referenced stable fixes
Discovery Timeline
- 2026-09-04 - CVE-2026-80815 published to NVD
- 2026-09-04 - Last updated in NVD database
Technical Details for CVE-2026-80815
Vulnerability Analysis
The defect stems from URB (USB Request Block) ownership confusion between the generic ALSA USB mixer code and the vendor-specific scarlett2 driver. scarlett2_init_notify() attempted to submit a notification URB using mixer->urb, a resource that mixer.c already allocates and manages for the UAC2 status interrupt endpoint.
When the device exposes the UAC2 status endpoint, usb_submit_urb() detects the URB is already active. The function silently returns 0, skipping notification setup entirely. The cmd_done completion object is never initialized because its setup lives past the failing check.
Subsequent execution of scarlett2_usb_init() issues the SCARLETT2_USB_INIT_1 command and calls wait_for_completion_timeout() on the uninitialized completion. The kernel then dereferences a zeroed wait.head list, causing a crash [CWE-908: Use of Uninitialized Resource].
Root Cause
The root cause is shared ownership of a single URB structure between two subsystems with incompatible lifecycle assumptions. mixer.c freed the URB in snd_usb_mixer_free() and resubmitted it in snd_usb_mixer_activate(), while scarlett2 assumed exclusive use. The cmd_done completion was initialized only on a code path that could be skipped, leaving stale zeroed memory reachable by the wait primitive.
Attack Vector
Exploitation requires local access with the ability to attach or interact with a Focusrite Scarlett USB device that exposes the UAC2 status interrupt endpoint. Loading the driver against such a device triggers the crash path during initialization. The fix introduces a private URB in scarlett2_data, moves cmd_done initialization into scarlett2_init_private(), and adds scarlett2_cleanup_urb() plus a private_resume callback to correctly re-establish the URB after suspend. reinit_completion() clears stale completion state before subsequent commands.
See the upstream fixes referenced in the kernel stable tree commit 013448eb and related backports for technical details.
Detection Methods for CVE-2026-80815
Indicators of Compromise
- Kernel oops or panic traces referencing wait_for_completion_timeout, scarlett2_usb_init, or scarlett2_init_notify in dmesg output
- Unexpected reboots or system hangs coinciding with connection of Focusrite Scarlett USB audio interfaces
- snd_usb_audio module logs showing repeated URB submission errors for the mixer status endpoint
Detection Strategies
- Inventory Linux endpoints running kernel versions predating the fix commits and cross-reference against Focusrite Scarlett USB device presence via lsusb telemetry
- Monitor kernel ring buffer and journalctl -k for stack traces mentioning scarlett2 symbols
- Correlate USB device attach events with subsequent kernel instability using host telemetry pipelines
Monitoring Recommendations
- Forward kernel logs to centralized logging for pattern matching on scarlett2_ function names in panic traces
- Track kernel package versions across the fleet and alert on hosts running unpatched builds with USB audio hardware attached
- Enable crash-dump collection so post-mortem analysis can confirm the uninitialized-completion signature
How to Mitigate CVE-2026-80815
Immediate Actions Required
- Update to a Linux kernel version containing the upstream fixes referenced in the NVD advisory
- Restrict physical and administrative access to systems where Focusrite Scarlett USB devices are used until patches are applied
- Blacklist the snd_usb_audio module on systems that do not require USB audio functionality as a temporary control
Patch Information
The upstream fix replaces the shared mixer->urb with a private URB stored in scarlett2_data, initializes cmd_done in scarlett2_init_private(), and adds proper cleanup and resume callbacks. Apply patches from the stable kernel tree: commit 013448eb, commit 04df0232, commit 4305e4b5, commit cd17d6ff, and commit ecd2f83a.
Workarounds
- Unload or blacklist the snd_usb_audio kernel module on hosts that do not require USB audio
- Physically disconnect affected Focusrite Scarlett USB devices from vulnerable Linux systems until the kernel is patched
- Disable USB port access via udev rules or BIOS controls on systems where USB audio is not required
# Blacklist snd_usb_audio until patched kernel is deployed
echo "blacklist snd_usb_audio" | sudo tee /etc/modprobe.d/blacklist-snd-usb-audio.conf
sudo modprobe -r snd_usb_audio
sudo update-initramfs -u
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.