CVE-2026-64483 PUBLISHED

ALSA: firewire: isight: bound the sample count to the packet payload

Assigner: Linux
Reserved: 19.07.2026 Published: 25.07.2026 Updated: 25.07.2026

In the Linux kernel, the following vulnerability has been resolved:

ALSA: firewire: isight: bound the sample count to the packet payload

isight_packet() takes the frame count from the device iso packet and checks it only against the device claimed iso length.

<pre>count = be32_to_cpu(payload->sample_count); if (likely(count <= (length - 16) / 4)) isight_samples(isight, payload->samples, count); </pre>

length is the iso header data_length. It can be up to 0xffff. So the gate allows a count up to about 16379. isight_samples() then copies count frames out of payload->samples into the PCM DMA buffer.

payload->samples holds only 2 * MAX_FRAMES_PER_PACKET values. The device multiplexes two samples per frame. A count past MAX_FRAMES_PER_PACKET reads past the payload. A count past the buffer size writes past runtime->dma_area. The smallest PCM buffer is larger than MAX_FRAMES_PER_PACKET. Bounding the count to MAX_FRAMES_PER_PACKET keeps both the read and the write in range.

A malicious or faulty Apple iSight on the FireWire bus reaches this during a normal capture.

Add the MAX_FRAMES_PER_PACKET bound to the gate.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 3a691b28a0ca3cf4d9010c6158318159e0275d2c to 24423e0a9251d348c3f1fb0bb0e61b879e1e976c (excl.)
  • affected from 3a691b28a0ca3cf4d9010c6158318159e0275d2c to ebbffacda6733dcbcef601b5b523460f8d8b671e (excl.)
  • affected from 3a691b28a0ca3cf4d9010c6158318159e0275d2c to 57e4d9043afc1eaddee8f50d11def6e65415d273 (excl.)
  • affected from 3a691b28a0ca3cf4d9010c6158318159e0275d2c to 3ed2fa1ed8cc65f910b8bbc0be3cc366b30f8478 (excl.)
  • affected from 3a691b28a0ca3cf4d9010c6158318159e0275d2c to 31da82b9676c6b112e7c72c7529e6812b919742a (excl.)
  • affected from 3a691b28a0ca3cf4d9010c6158318159e0275d2c to 8e48a29813df8dd71503800b7acf69c12c035045 (excl.)
  • affected from 3a691b28a0ca3cf4d9010c6158318159e0275d2c to 31a01b70bb90e3ef3147f308e2ea899e1d2485ca (excl.)
  • affected from 3a691b28a0ca3cf4d9010c6158318159e0275d2c to 29b9667982e4df2ed7744f86b1144f8bb58eb698 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 3.0 is affected
  • unaffected from 0 to 3.0 (excl.)
  • unaffected from 5.10.261 to 5.10.* (incl.)
  • unaffected from 5.15.212 to 5.15.* (incl.)
  • unaffected from 6.1.178 to 6.1.* (incl.)
  • unaffected from 6.6.145 to 6.6.* (incl.)
  • unaffected from 6.12.96 to 6.12.* (incl.)
  • unaffected from 6.18.39 to 6.18.* (incl.)
  • unaffected from 7.1.4 to 7.1.* (incl.)
  • unaffected from 7.2-rc1 to * (incl.)

References