CyberRota Analysis
AI-GeneratedThe vulnerability affects the Linux kernel's ALSA subsystem, specifically in the handling of legacy conversion arrays for USB MIDI 2.0 devices. A double free condition occurs when memory allocated for the conversion array is freed but not properly nullified, potentially leading to memory corruption and system instability. Users and administrators of systems utilizing the Linux kernel with USB MIDI devices should prioritize addressing this issue to prevent potential exploitation and ensure system reliability.
Original NVD Description
In the Linux kernel, the following vulnerability has been resolved: ALSA: ump: fix double free of out_cvts on rawmidi error snd_ump_attach_legacy_rawmidi() allocates the legacy conversion array ump->out_cvts and, on the snd_rawmidi_new() error path, frees it with kfree() but leaves ump->out_cvts pointing at the freed memory. When the endpoint is later torn down, snd_ump_endpoint_free() frees ump->out_cvts a second time, resulting in a double free. The host snd-usb-audio driver attaches the legacy rawmidi for any USB MIDI 2.0 (UMP) device, so a device that makes snd_rawmidi_new() fail reaches this path on enumeration. Clear ump->out_cvts after freeing it on the error path so it is not freed again during teardown. Discovered by XBOW, triaged by Baul Lee <baul.lee@xbow.com>