CVE-2026-46184 Details
Description
In the Linux kernel, the following vulnerability has been resolved: sound: ua101: fix division by zero at probe Add a missing sanity check for bNrChannels in detect_usb_format() to prevent a division by zero in playback_urb_complete() and capture_urb_complete(). USB core does not validate class-specific descriptor fields such as bNrChannels, so drivers must verify them before use. If a device provides bNrChannels = 0, frame_bytes becomes zero and is later used as a divisor in the URB completion handlers, leading to a kernel crash.
A vulnerability in the Linux kernel's USB audio driver for the Edirol UA-101 device can lead to a kernel crash. This issue arises from a division by zero error in the URB (USB Request Block) completion handlers. The root cause is a missing sanity check for the 'bNrChannels' field in the USB format detection function. When a device reports zero channels, it creates a scenario where the frame bytes calculation results in zero, which is then improperly used as a divisor, causing a crash. The USB core does not validate this class-specific descriptor, leaving it to drivers to ensure its correctness before use.
Users can update to the latest version of the Linux kernel where this vulnerability has been addressed. Instructions for updating the kernel can be found in the documentation for the specific Linux distribution in use.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/0ff2b713f406e9ecadb406014d74e7a020ac12b1 | kernel.org | Patch |
| https://git.kernel.org/stable/c/593dd7e6c890d8e4ca21b3e2f796b7cb8e8da983 | kernel.org | Patch |
| https://git.kernel.org/stable/c/6162e8212e88c39492d981b248b5e37002486c66 | kernel.org | Patch |
| https://git.kernel.org/stable/c/66d9c2ed081f299cfb201d9e9c4faf920e56e0bf | kernel.org | Patch |
| https://git.kernel.org/stable/c/aae1498c59f48d03ee358df84f07a5af9885f827 | kernel.org | Patch |
| https://git.kernel.org/stable/c/d1f73f169c1014463b5060e3f60813e13ddc7b87 | kernel.org | Patch |
| https://git.kernel.org/stable/c/e02897c5b041c9b980055fa9a6167023d6dc5caf | kernel.org | Patch |
| https://git.kernel.org/stable/c/f1862dbf09080254c52175a448290c784dd7d3de | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-369 | Divide By Zero | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 2.6.34, < 5.10.258 >= 5.11, < 5.15.209 >= 5.16, < 6.1.175 >= 6.2, < 6.6.140 >= 6.7, < 6.12.88 >= 6.13, < 6.18.30 >= 6.19, < 7.0.7 7.1 rc1 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | kernel.org |
| Jun 11, 2026 | Initial Analysis | [email protected] |
| Jun 1, 2026 | CVE Modified | kernel.org |
| May 28, 2026 | New CVE Received | kernel.org |