CVE-2026-80971 Overview
CVE-2026-80971 is a use-after-free vulnerability in the Linux kernel's ALSA bcd2000 USB MIDI driver. The bcd2000_free_usb_related_resources() function releases both the MIDI input and output URBs on device disconnect but leaves the pointers intact. Because the rawmidi device outlives that call, an open substream can still reach bcd2000_midi_send() from the trigger path and write to freed memory before submitting the URB to the USB core. A concurrent submission racing the disconnect can also requeue an URB after it has been reaped, and the input completion handler can resubmit midi_in_urb in the same fashion.
Critical Impact
A local attacker with access to a bcd2000 MIDI device can trigger a slab use-after-free during USB disconnect, leading to kernel memory corruption and potential local privilege escalation.
Affected Products
- Linux kernel sound/usb/bcd2000 driver (snd_bcd2000 module)
- Multiple stable branches, per the eight upstream fix commits published on git.kernel.org
- Confirmed reproducible on Linux 7.2.0-rc5 (arm64) via KASAN
Discovery Timeline
- Discovery - Vulnerability discovered by XBOW and triaged by Baul Lee
- 2026-09-11 - CVE-2026-80971 published to NVD
- 2026-09-14 - Last updated in NVD database
Technical Details for CVE-2026-80971
Vulnerability Analysis
The flaw is a classic use-after-free in a USB device disconnect path. bcd2000_free_usb_related_resources() calls usb_kill_urb() followed by usb_free_urb() on midi_out_urb and midi_in_urb, but does not NULL the pointers. The ALSA rawmidi device remains registered after this cleanup completes, so any substream still open when the device is unplugged can execute the trigger path on close. That path enters bcd2000_midi_send(), which writes transfer_buffer_length on the freed URB and then calls usb_submit_urb() on it.
KASAN on kernel 7.2.0-rc5 (arm64) captured both sides of the race: a slab-use-after-free write of size 4 in bcd2000_midi_send and a slab-use-after-free read of size 8 in usb_submit_urb, both freed by usb_free_urb inside bcd2000_disconnect. Successful exploitation grants kernel-mode memory corruption from a local, low-privileged context.
Root Cause
The driver treats URB teardown as terminal but never invalidates the pointers or blocks future submissions. usb_kill_urb() waits for in-flight I/O but does not prevent a subsequent usb_submit_urb() from resubmitting the URB after it has been freed, so both the rawmidi trigger path and the input completion handler can requeue reaped memory.
Attack Vector
Exploitation requires local access with the ability to open the ALSA rawmidi character device exposed by an attached Behringer BCD2000 controller, or an equivalent emulated USB device. The attacker keeps a MIDI substream open and races a USB disconnect against a write or completion event. The disconnect frees the URB while the trigger or completion path dereferences and submits it, corrupting the slab allocator and providing a primitive suitable for local privilege escalation.
No public exploit is currently available. See the upstream commits such as Linux Kernel Commit 3c00004f and Linux Kernel Commit 9af0867 for the exact code changes.
Detection Methods for CVE-2026-80971
Indicators of Compromise
- KASAN reports referencing slab-use-after-free in bcd2000_midi_send or usb_submit_urb with the snd_bcd2000 module in the call stack.
- Kernel oops or panic messages that name bcd2000_disconnect, bcd2000_midi_output_trigger, or bcd2000_input_complete immediately after a USB disconnect event.
- Unexpected snd_bcd2000 module loads on servers or workstations where MIDI hardware is not sanctioned.
Detection Strategies
- Enable KASAN on test and staging kernels to surface use-after-free writes and reads in the ALSA USB code path before production deployment.
- Monitor dmesg and /var/log/kern.log for BUG: KASAN or general protection fault entries correlated with usb 1-*: USB disconnect events.
- Track process behavior that opens /dev/snd/midiC*D* handles across USB disconnect and reconnect cycles, which is atypical for most enterprise endpoints.
Monitoring Recommendations
- Alert on loading of the snd_bcd2000 kernel module on systems where MIDI hardware is not part of the approved baseline.
- Ingest kernel logs into the SIEM and build detections on the strings bcd2000_midi_send, bcd2000_disconnect, and slab-use-after-free.
- Correlate USB device attach and detach events from udev with local user session activity to identify race-condition attempts.
How to Mitigate CVE-2026-80971
Immediate Actions Required
- Apply the upstream Linux kernel patches referenced in the NVD entry as soon as your distribution ships them.
- Blacklist the snd_bcd2000 module on systems that do not require Behringer BCD2000 MIDI functionality.
- Restrict physical and virtual USB access on multi-user hosts to reduce the local attack surface.
Patch Information
The fix clears both URB pointers after freeing and tests them on any path that can still execute after disconnect. It also replaces usb_kill_urb() with usb_poison_urb(), which waits for a running completion handler and rejects any later submission, quiescing the input path. See the upstream commits: 3c00004f, 459d3a6, 5a77feb, 6c07aad, 7df3194, 9af0867, b06ebc7, and eb482a0.
Workarounds
- Prevent the vulnerable driver from loading by adding it to the modprobe blacklist on hosts without a legitimate use case.
- Enforce USB device allow-listing through USBGuard or equivalent tooling to block untrusted MIDI controllers.
- Limit interactive local access on shared systems until the patched kernel is deployed.
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
