CVE-2026-64601 is a vulnerability in Linux Kernel
Published on August 6, 2026
ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on each resubmission
In the Linux kernel, the following vulnerability has been resolved:
ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on each resubmission
In capture_urb_complete(), usb_anchor_urb() is called on every
completion callback, but the URB is already anchored from the
initial submission in tascam_trigger_start(). Each redundant call
corrupts the anchor's doubly-linked list and inflates the URB
refcount. When usb_kill_anchored_urbs() traverses the list during
stream stop / suspend / disconnect, the corrupted list leads to
use-after-free.
Remove the redundant usb_anchor_urb() from the resubmit path.
Products Associated with CVE-2026-64601
Want to know whenever a new CVE is published for Linux Kernel? stack.watch will email you.
Affected Versions
Linux:- Version c1bb0c13e430623c26543baae5bb9ae21139db87 and below 16f14f55141d4c55c3f321f93c328fff7cd6860a is affected.
- Version c1bb0c13e430623c26543baae5bb9ae21139db87 and below ab1db64912428cdf06a4f9542e16e0575e9ad59f is affected.
- Version c1bb0c13e430623c26543baae5bb9ae21139db87 and below 5cff1529a2f9b3461a7f5a6e36a86682fc290534 is affected.
- Version 6.18 is affected.
- Before 6.18 is unaffected.
- Version 6.18.39, <= 6.18.* is unaffected.
- Version 7.1.4, <= 7.1.* is unaffected.
- Version 7.2-rc2, <= * is unaffected.