Skip to main content
Vulnerability Database/CVE-2026-80816

CVE-2026-80816: Linux Kernel ALSA FCP Use-After-Free Flaw

CVE-2026-80816 is a use-after-free vulnerability in the Linux kernel ALSA FCP component that can cause system crashes through improper URB handling. This article covers technical details, affected versions, and mitigation strategies.

Published:

CVE-2026-80816 Overview

CVE-2026-80816 affects the Linux kernel's Advanced Linux Sound Architecture (ALSA) subsystem, specifically the Focusrite Control Protocol (FCP) driver. The flaw exists in fcp_init_notify(), which incorrectly shared mixer->urb with snd_usb_mixer_status_create(). On devices exposing a UAC2 status interrupt endpoint, the early return path skips notification URB submission and leaves cmd_done uninitialized. Subsequent calls to fcp_init() trigger wait_for_completion_timeout() against a zeroed wait.head, causing a kernel crash. The upstream fix introduces a dedicated URB in fcp_data and properly initializes the completion structure.

Critical Impact

Local users with access to a Focusrite USB audio device can trigger a kernel crash through the ALSA FCP driver, resulting in denial of service on affected Linux systems.

Affected Products

  • Linux kernel versions containing the ALSA FCP driver with the vulnerable fcp_init_notify() implementation
  • Distributions shipping kernels prior to the commits referenced in the upstream stable tree
  • Systems using Focusrite USB audio interfaces exposing UAC2 status interrupt endpoints

Discovery Timeline

  • 2026-09-04 - CVE-2026-80816 published to NVD
  • 2026-09-04 - Last updated in NVD database

Technical Details for CVE-2026-80816

Vulnerability Analysis

The vulnerability resides in the ALSA Focusrite Control Protocol driver's notification setup routine. fcp_init_notify() reused mixer->urb, a USB Request Block (URB) allocated by snd_usb_mixer_status_create() for the optional UAC2 status interrupt endpoint. When a device exposes that endpoint, the function's "already set up" early return path fires against the status URB and returns success without submitting an FCP notification URB.

Because cmd_done is initialized only after that early return, it remains zeroed. When fcp_init() subsequently issues init1_opcode and calls wait_for_completion_timeout(), the kernel operates on an uninitialized wait.head, producing a crash. Additionally, fcp_cleanup_urb() would incorrectly kill and free the mixer.c-owned status URB, causing further use-after-free conditions in the USB mixer teardown path.

Root Cause

The root cause is improper resource sharing between two independent subsystems. The FCP notification logic treated a URB owned and lifecycle-managed by mixer.c as its own, resulting in uninitialized completion state and duplicate free operations during cleanup.

Attack Vector

Exploitation requires local access to a Linux host with a Focusrite USB audio device attached that exposes a UAC2 status interrupt endpoint. A malicious or malformed USB device presenting the appropriate descriptors could trigger the code path during driver initialization or resume from suspend via fcp_reinit().

The vulnerability manifests during normal FCP initialization and post-suspend re-initialization. See the referenced kernel commits for the specific code changes: Kernel Git Commit 5da21a4 and Kernel Git Commit 918b8d2.

Detection Methods for CVE-2026-80816

Indicators of Compromise

  • Unexpected kernel panics or oops messages referencing wait_for_completion_timeout and the ALSA FCP driver
  • Kernel logs containing warnings from snd_usb_mixer_status_create or FCP notification failures
  • System crashes shortly after connecting Focusrite USB audio interfaces or resuming from suspend

Detection Strategies

  • Audit kernel versions across the fleet to identify hosts running versions that predate the upstream fix commits
  • Correlate USB device connection events with kernel crash reports referencing ALSA FCP call stacks
  • Review dmesg output for FCP driver initialization failures and completion-related warnings

Monitoring Recommendations

  • Enable kernel crash dump collection (kdump) on Linux endpoints to capture stack traces for post-incident analysis
  • Monitor /var/log/kern.log and journalctl -k for repeated ALSA FCP driver anomalies
  • Track USB device enumeration events on multi-user or lab systems where physical device access is uncontrolled

How to Mitigate CVE-2026-80816

Immediate Actions Required

  • Update to a Linux kernel build that includes the upstream fix commits referenced by the stable tree
  • Prioritize patching workstations, audio production systems, and laboratory hosts that use Focusrite USB audio hardware
  • Restrict physical USB access on shared or unattended systems until patches are applied

Patch Information

The upstream fix introduces a dedicated URB inside fcp_data, initializes cmd_done in fcp_init_private() where fcp_data is allocated, and uses reinit_completion() to clear stale state during re-initialization via fcp_reinit(). Apply distribution kernel updates that include the following commits: Kernel Git Commit 5da21a4, Kernel Git Commit 65aceb4, Kernel Git Commit 6db3c1d, and Kernel Git Commit 918b8d2.

Workarounds

  • Blacklist the vulnerable ALSA FCP driver module on systems that do not require Focusrite USB audio support
  • Physically disconnect affected Focusrite USB audio devices until the kernel is patched
  • Disable USB hot-plug for audio class devices on production systems using udev rules where feasible
bash
# Blacklist the FCP driver module until the kernel is patched
echo "blacklist snd_usb_audio" | sudo tee /etc/modprobe.d/blacklist-fcp.conf
sudo update-initramfs -u

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.