In the Linux kernel, the following vulnerability has been resolved:
ALSA: usb-audio: Drop snd_BUG_ON() from snd_usbmidi_output_open()
snd_usbmidi_output_open() has a check of the NULL port with snd_BUG_ON(). snd_BUG_ON() was used as this shouldn't have happened, but in reality, the NULL port may be seen when the device gives an invalid endpoint setup at the descriptor, hence the driver skips the allocation. That is, the check itself is valid and snd_BUG_ON() should be dropped from there. Otherwise it's confusing as if it were a real bug, as recently syzbot stumbled on it.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade linux | May 5, 2025 | May 1, 2025 |
| Huawei Euleros 2_0_sp13 | — | Upgrade kernelUpgrade kernel-tools-libsUpgrade bpftoolUpgrade kernel-toolsUpgrade kernel-abi-stablelistsUpgrade python3-perf | Oct 24, 2025 | Oct 23, 2025 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | May 1, 2025 |
| Ubuntu | — | Upgrade linuxUpgrade linux-lowlatencyUpgrade linux-iotUpgrade linux-nvidiaUpgrade linux-raspiUpgrade linux-oracle-5.15Upgrade linux-aws-hweUpgrade linux-azure-5.4Upgrade linux-aws-5.4Upgrade linux-gcp-fipsUpgrade linux-hwe-5.4Upgrade linux-xilinx-zynqmpUpgrade linux-gkeopUpgrade linux-ibm-5.4Upgrade linux-gkeUpgrade linux-azure-fipsUpgrade linux-azure-5.15Upgrade linux-hwe-5.15Upgrade linux-azure-fde-5.15Upgrade linux-gcp-5.4Upgrade linux-ibmUpgrade linux-intel-iotg-5.15Upgrade linux-aws-fipsUpgrade linux-hweUpgrade linux-oracleUpgrade linux-aws-5.15Upgrade linux-gcpUpgrade linux-fipsUpgrade linux-raspi-5.4Upgrade linux-bluefieldUpgrade linux-nvidia-tegra-5.15Upgrade linux-intel-iotgUpgrade linux-azureUpgrade linux-oracle-5.4Upgrade linux-realtimeUpgrade linux-azure-4.15Upgrade linux-gcp-4.15Upgrade linux-intel-iot-realtimeUpgrade linux-awsUpgrade linux-kvmUpgrade linux-riscv-5.15Upgrade linux-gcp-5.15Upgrade linux-lowlatency-hwe-5.15 | May 6, 2025 | May 1, 2025 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | May 27, 2026 | May 1, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub