CVE-2026-80816 Overview
CVE-2026-80816 affects the Linux kernel's Advanced Linux Sound Architecture (ALSA) subsystem, specifically the Focusrite Control Protocol (FCP) driver. The flaw exists in fcp_init_notify(), which incorrectly shared mixer->urb with snd_usb_mixer_status_create(). On devices exposing a UAC2 status interrupt endpoint, the early return path skips notification URB submission and leaves cmd_done uninitialized. Subsequent calls to fcp_init() trigger wait_for_completion_timeout() against a zeroed wait.head, causing a kernel crash. The upstream fix introduces a dedicated URB in fcp_data and properly initializes the completion structure.
Critical Impact
Local users with access to a Focusrite USB audio device can trigger a kernel crash through the ALSA FCP driver, resulting in denial of service on affected Linux systems.
Affected Products
- Linux kernel versions containing the ALSA FCP driver with the vulnerable fcp_init_notify() implementation
- Distributions shipping kernels prior to the commits referenced in the upstream stable tree
- Systems using Focusrite USB audio interfaces exposing UAC2 status interrupt endpoints
Discovery Timeline
- 2026-09-04 - CVE-2026-80816 published to NVD
- 2026-09-04 - Last updated in NVD database
Technical Details for CVE-2026-80816
Vulnerability Analysis
The vulnerability resides in the ALSA Focusrite Control Protocol driver's notification setup routine. fcp_init_notify() reused mixer->urb, a USB Request Block (URB) allocated by snd_usb_mixer_status_create() for the optional UAC2 status interrupt endpoint. When a device exposes that endpoint, the function's "already set up" early return path fires against the status URB and returns success without submitting an FCP notification URB.
Because cmd_done is initialized only after that early return, it remains zeroed. When fcp_init() subsequently issues init1_opcode and calls wait_for_completion_timeout(), the kernel operates on an uninitialized wait.head, producing a crash. Additionally, fcp_cleanup_urb() would incorrectly kill and free the mixer.c-owned status URB, causing further use-after-free conditions in the USB mixer teardown path.
Root Cause
The root cause is improper resource sharing between two independent subsystems. The FCP notification logic treated a URB owned and lifecycle-managed by mixer.c as its own, resulting in uninitialized completion state and duplicate free operations during cleanup.
Attack Vector
Exploitation requires local access to a Linux host with a Focusrite USB audio device attached that exposes a UAC2 status interrupt endpoint. A malicious or malformed USB device presenting the appropriate descriptors could trigger the code path during driver initialization or resume from suspend via fcp_reinit().
The vulnerability manifests during normal FCP initialization and post-suspend re-initialization. See the referenced kernel commits for the specific code changes: Kernel Git Commit 5da21a4 and Kernel Git Commit 918b8d2.
Detection Methods for CVE-2026-80816
Indicators of Compromise
- Unexpected kernel panics or oops messages referencing wait_for_completion_timeout and the ALSA FCP driver
- Kernel logs containing warnings from snd_usb_mixer_status_create or FCP notification failures
- System crashes shortly after connecting Focusrite USB audio interfaces or resuming from suspend
Detection Strategies
- Audit kernel versions across the fleet to identify hosts running versions that predate the upstream fix commits
- Correlate USB device connection events with kernel crash reports referencing ALSA FCP call stacks
- Review dmesg output for FCP driver initialization failures and completion-related warnings
Monitoring Recommendations
- Enable kernel crash dump collection (kdump) on Linux endpoints to capture stack traces for post-incident analysis
- Monitor /var/log/kern.log and journalctl -k for repeated ALSA FCP driver anomalies
- Track USB device enumeration events on multi-user or lab systems where physical device access is uncontrolled
How to Mitigate CVE-2026-80816
Immediate Actions Required
- Update to a Linux kernel build that includes the upstream fix commits referenced by the stable tree
- Prioritize patching workstations, audio production systems, and laboratory hosts that use Focusrite USB audio hardware
- Restrict physical USB access on shared or unattended systems until patches are applied
Patch Information
The upstream fix introduces a dedicated URB inside fcp_data, initializes cmd_done in fcp_init_private() where fcp_data is allocated, and uses reinit_completion() to clear stale state during re-initialization via fcp_reinit(). Apply distribution kernel updates that include the following commits: Kernel Git Commit 5da21a4, Kernel Git Commit 65aceb4, Kernel Git Commit 6db3c1d, and Kernel Git Commit 918b8d2.
Workarounds
- Blacklist the vulnerable ALSA FCP driver module on systems that do not require Focusrite USB audio support
- Physically disconnect affected Focusrite USB audio devices until the kernel is patched
- Disable USB hot-plug for audio class devices on production systems using udev rules where feasible
# Blacklist the FCP driver module until the kernel is patched
echo "blacklist snd_usb_audio" | sudo tee /etc/modprobe.d/blacklist-fcp.conf
sudo update-initramfs -u
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.