CVE-2026-64601 Details
Description
In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on each resubmission In capture_urb_complete(), usb_anchor_urb() is called on every completion callback, but the URB is already anchored from the initial submission in tascam_trigger_start(). Each redundant call corrupts the anchor's doubly-linked list and inflates the URB refcount. When usb_kill_anchored_urbs() traverses the list during stream stop / suspend / disconnect, the corrupted list leads to use-after-free. Remove the redundant usb_anchor_urb() from the resubmit path.
A vulnerability in the Linux kernel's ALSA USB audio driver for the Tascam US-144MKII has been addressed. The issue arose because the function 'capture_urb_complete()' called 'usb_anchor_urb()' on every completion callback, even though the URB (USB Request Block) was already anchored from the initial submission. This redundant anchoring corrupted the anchor's doubly-linked list and increased the URB reference count. When 'usb_kill_anchored_urbs()' processed the list during stream stop, suspend, or disconnect, the corrupted list caused a use-after-free condition. The vulnerability has been fixed by removing the unnecessary 'usb_anchor_urb()' call from the resubmission path.
Users can upgrade to the latest version of the Linux kernel where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
No weakness enumeration is available for this CVE.
Affected Products
No affected product data is available for this CVE.
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 17, 2026 | CVE Modified | kernel.org |
| Aug 8, 2026 | CVE Modified | kernel.org |
| Aug 6, 2026 | New CVE Received | kernel.org |