In the Linux kernel, the following vulnerability has been resolved: ALSA: line6: fix stack overflow in line6_midi_transmit Correctly calculate available space including the size of the chunk buffer. This fixes a buffer overflow when multiple MIDI sysex messages are sent to a PODxt device.
Update Linux/Linux to b026af92b2cea907c780f7168c730c816cd33311 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanALSA: line6: fix stack overflow in line6_midi_transmit affects Linux/Linux (generic), Linux/Linux (generic). Severity is high. In the Linux kernel, the following vulnerability has been resolved: ALSA: line6: fix stack overflow in line6_midi_transmit Correctly calculate available space including the size of the chunk buffer. This fixes a buffer overflow when multiple MIDI sysex messages are sent to a PODxt device.
AI coding agents often install or upgrade packages automatically in generic. A high vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=f2459201c72e8f8553644505eed19954d4c3a023 <b026af92b2cea907c780f7168c730c816cd33311 || >=f2459201c72e8f8553644505eed19954d4c3a023 <49cb7737e733013ec86aa77ed2e19b94a68eaa05 || >=f2459201c72e8f8553644505eed19954d4c3a023 <0c76087449ee4ed45a88b10017d02c6694caedb1 || >=f2459201c72e8f8553644505eed19954d4c3a023 <25e8c6ecb46843a955f254b8f0d77894e4a53dc4 || >=f2459201c72e8f8553644505eed19954d4c3a023 <66f359ad66d49f75d39ac729f9114dabf90b81bb || >=f2459201c72e8f8553644505eed19954d4c3a023 <0c9118e381ff538874e00fd4e66a768273c150fb || >=f2459201c72e8f8553644505eed19954d4c3a023 <61e4be4a60cc6de723f8c574ddbcb3025eb44cac || >=f2459201c72e8f8553644505eed19954d4c3a023 <389d34c2a8b52acc351fd932ed4bea41fee5a39b || >=f2459201c72e8f8553644505eed19954d4c3a023 <b8800d324abb50160560c636bfafe2c81001b66c |
In the Linux kernel, the following vulnerability has been resolved: ALSA: line6: fix stack overflow in line6_midi_transmit Correctly calculate available space including the size of the chunk buffer. This fixes a buffer overflow when multiple MIDI sysex messages are sent to a PODxt device.
Update Linux/Linux to b026af92b2cea907c780f7168c730c816cd33311 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanALSA: line6: fix stack overflow in line6_midi_transmit affects Linux/Linux (generic), Linux/Linux (generic). Severity is high. In the Linux kernel, the following vulnerability has been resolved: ALSA: line6: fix stack overflow in line6_midi_transmit Correctly calculate available space including the size of the chunk buffer. This fixes a buffer overflow when multiple MIDI sysex messages are sent to a PODxt device.
AI coding agents often install or upgrade packages automatically in generic. A high vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=f2459201c72e8f8553644505eed19954d4c3a023 <b026af92b2cea907c780f7168c730c816cd33311 || >=f2459201c72e8f8553644505eed19954d4c3a023 <49cb7737e733013ec86aa77ed2e19b94a68eaa05 || >=f2459201c72e8f8553644505eed19954d4c3a023 <0c76087449ee4ed45a88b10017d02c6694caedb1 || >=f2459201c72e8f8553644505eed19954d4c3a023 <25e8c6ecb46843a955f254b8f0d77894e4a53dc4 || >=f2459201c72e8f8553644505eed19954d4c3a023 <66f359ad66d49f75d39ac729f9114dabf90b81bb || >=f2459201c72e8f8553644505eed19954d4c3a023 <0c9118e381ff538874e00fd4e66a768273c150fb || >=f2459201c72e8f8553644505eed19954d4c3a023 <61e4be4a60cc6de723f8c574ddbcb3025eb44cac || >=f2459201c72e8f8553644505eed19954d4c3a023 <389d34c2a8b52acc351fd932ed4bea41fee5a39b || >=f2459201c72e8f8553644505eed19954d4c3a023 <b8800d324abb50160560c636bfafe2c81001b66c |
| b026af92b2cea907c780f7168c730c816cd33311, 49cb7737e733013ec86aa77ed2e19b94a68eaa05, 0c76087449ee4ed45a88b10017d02c6694caedb1, 25e8c6ecb46843a955f254b8f0d77894e4a53dc4, 66f359ad66d49f75d39ac729f9114dabf90b81bb, 0c9118e381ff538874e00fd4e66a768273c150fb, 61e4be4a60cc6de723f8c574ddbcb3025eb44cac, 389d34c2a8b52acc351fd932ed4bea41fee5a39b, b8800d324abb50160560c636bfafe2c81001b66c |
| Linux/Linuxgeneric | 3.15 | Not reported |
|---|
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by CVE List V5 (cvelist).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard| b026af92b2cea907c780f7168c730c816cd33311, 49cb7737e733013ec86aa77ed2e19b94a68eaa05, 0c76087449ee4ed45a88b10017d02c6694caedb1, 25e8c6ecb46843a955f254b8f0d77894e4a53dc4, 66f359ad66d49f75d39ac729f9114dabf90b81bb, 0c9118e381ff538874e00fd4e66a768273c150fb, 61e4be4a60cc6de723f8c574ddbcb3025eb44cac, 389d34c2a8b52acc351fd932ed4bea41fee5a39b, b8800d324abb50160560c636bfafe2c81001b66c |
| Linux/Linuxgeneric | 3.15 | Not reported |
|---|
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by CVE List V5 (cvelist).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard