{"id":"AZL-103607","summary":"CVE-2026-93808 affecting package kernel 6.6.157.1-1","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: usb-audio: caiaq: validate EP1 reply lengths\n\nusb_ep1_command_reply_dispatch() uses buf[0] as a command byte and then\nreads command-specific fixed items from the same URB buffer. Several\npaths use buf + 1, buf[1], buf[2], or buf + 3 without first proving that\nurb-\u003eactual_length contains those bytes.\n\nAdd per-command length checks, use a payload length derived from the\nbytes after the command byte for the control-state copy, and reject short\nanalog input payloads before the input helper reads fixed offsets from\nthe EP1 reply.","modified":"2026-09-25T14:16:23.936429129Z","published":"2026-09-24T17:17:13Z","upstream":["CVE-2026-93808"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-93808"}],"affected":[{"package":{"name":"kernel","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/kernel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"6.6.157.1-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-103607.json"}}],"schema_version":"1.9.0"}