CVE-2026-23318Patch(linux / linux_kernel)

LOWCVSS 7.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch linux linux_kernel systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Use correct version for UAC3 header validation The entry of the validators table for UAC3 AC header descriptor is defined with the wrong protocol version UAC_VERSION_2, while it should have been UAC_VERSION_3. This results in the validator never matching for actual UAC3 devices (protocol == UAC_VERSION_3), causing their header descriptors to bypass validation entirely. A malicious USB device presenting a truncated UAC3 header could exploit this to cause out-of-bounds reads when the driver later accesses unvalidated descriptor fields. The bug was introduced in the same commit as the recently fixed UAC3 feature unit sub-type typo, and appears to be from the same copy-paste error when the UAC3 section was created from the UAC2 section.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-125

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • linux_kernel

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-03-25); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
linux_kernel

2 versions affected across 1 product

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-03-25: 1Mentions · 2026-03-26: 1Mentions · 2026-03-28: 1Patch / Workaround · 2026-03-25: 1Technical Details · 2026-03-25: 1Technical Details · 2026-03-26: 103-2503-2603-28
Signal classification3 categories
Patch
133.3%
Disclosure
133.3%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-251
Patch1
2026-03-261
Disclosure1
2026-03-281
General1
Full discourse3 posts
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-23318 🚨 Risk Level: Unknown 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-23318 #CVE-2026-23318 #CVE   #CyberSecurity #InfoSec https://t.co/5S6b5VLjUQ

    Post summary

    The tweet simply announces CVE‑2026‑23318 with minimal details and no indication of PoC, exploitation, patch, or technical specifics.

    0000024
    123 followersView on X
  • WindowsForum@windowsforum
    Disclosure

    🚨 Another day, another “whoops” in kernel validation: a UAC3 header slips past because the version check targets the wrong protocol. Congrats, attackers love typos. #WindowsForum #Security #Kernel https://windowsforum.com/threads/cve-2026-23318-uac3-usb-audio-validator-typo-risks-kernel-out-of-bounds-reads.407413/ #LinuxKernel #UsbAudio #CveSecurity #AlsaSndUsbAudio https://t.co/RN3hzwKf13

    Post summary

    The tweet announces a kernel validation flaw (CVE‑2026‑23318) that allows out‑of‑bounds reads via a mis‑validated UAC3 header, but no PoC, exploit, or patch is provided.

    0000025
    1.0K followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-23318 In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Use correct version for UAC3 header validation The entry of the validators tabl… https://www.cve.org/CVERecord?id=CVE-2026-23318

    Post summary

    CVE-2026-23318 – a Linux kernel ALSA issue involving UAC3 header validation – has been resolved, with no PoC, exploit, or active exploitation reported.

    00000140
    56.8K followersView on X
CPE platform detail9 entries

9 of 9 entries

PartVendorProductVersionTarget SWTarget HW
OSlinuxlinux_kernel---
OSlinuxlinux_kernel5.4--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--

Explore more