Linux Kernel NULL Dereference Vulnerability in ALSA USB-Audio Driver for Scarlett2 Mixer

Vulnerability

A vulnerability in the Linux kernel's USB-audio driver for Scarlett2 mixers can lead to a NULL pointer dereference. This issue arises when a malformed USB descriptor is received, as the driver expects an endpoint to be present in the parsed interface. The vulnerability has been reported by a fuzzer.

Impact

Exploitation of this vulnerability can cause a NULL pointer dereference, leading to a crash of the affected application or service.

Reproduction

The vulnerability can be reproduced by sending a malformed USB descriptor to a device using the Scarlett2 mixer. This can be done using a USB fuzzer that targets the audio interface.

Remediation

Users can upgrade to the latest version of the Linux kernel where this vulnerability has been patched.

Added: May 8, 2026, 8:18 PM
Updated: May 8, 2026, 8:18 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
2.5
exploitability
2.9
remediation
7.7
relevance
7.8
threat
4.8
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.