Answer in brief
CVE-2026-74502 records a Unknown severity vulnerability in ALSA: ump: fix double free of out_cvts on rawmidi error. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=33cd7630782df2230529c3e8f1a6d0ae9cd6ab49 <e84d2e53a05c78a04d1343eeb0f31a79456e79fc || >=33cd7630782df2230529c3e8f1a6d0ae9cd6ab49 <3302aaeac4f7ee6b775850db21d5f61064ce70ad || >=33cd7630782df2230529c3e8f1a6d0ae9cd6ab49 <032746c2dd9a4ea0774b04ac8a29e2ea628f106e || >=33cd7630782df2230529c3e8f1a6d0ae9cd6ab49 <c57001f55f97ef856fb6527e376c5c4a056a53a4 || >=33cd7630782df2230529c3e8f1a6d0ae9cd6ab49 <70c977815af0d997feb2d0c5d284d55689bf7051 | e84d2e53a05c78a04d1343eeb0f31a79456e79fc, 3302aaeac4f7ee6b775850db21d5f61064ce70ad, 032746c2dd9a4ea0774b04ac8a29e2ea628f106e, c57001f55f97ef856fb6527e376c5c4a056a53a4, 70c977815af0d997feb2d0c5d284d55689bf7051 |
| Linux/Linuxgeneric | 6.5 | Not reported |
Published upstream
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 15, 2026
In the Linux kernel, the following vulnerability has been resolved: ALSA: ump: fix double free of out_cvts on rawmidi error snd_ump_attach_legacy_rawmidi() allocates the legacy conversion array ump->out_cvts and, on the snd_rawmidi_new() error path, frees it with kfree() but leaves ump->out_cvts pointing at the freed memory. When the endpoint is later torn down, snd_ump_endpoint_free() frees ump->out_cvts a second time, resulting in a double free. The host snd-usb-audio driver attaches the legacy rawmidi for any USB MIDI 2.0 (UMP) device, so a device that makes snd_rawmidi_new() fail reaches this path on enumeration. Clear ump->out_cvts after freeing it on the error path so it is not freed again during teardown. Discovered by XBOW, triaged by Baul Lee <[email protected]>
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2026-74502 records a Unknown severity vulnerability in ALSA: ump: fix double free of out_cvts on rawmidi error. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=33cd7630782df2230529c3e8f1a6d0ae9cd6ab49 <e84d2e53a05c78a04d1343eeb0f31a79456e79fc || >=33cd7630782df2230529c3e8f1a6d0ae9cd6ab49 <3302aaeac4f7ee6b775850db21d5f61064ce70ad || >=33cd7630782df2230529c3e8f1a6d0ae9cd6ab49 <032746c2dd9a4ea0774b04ac8a29e2ea628f106e || >=33cd7630782df2230529c3e8f1a6d0ae9cd6ab49 <c57001f55f97ef856fb6527e376c5c4a056a53a4 || >=33cd7630782df2230529c3e8f1a6d0ae9cd6ab49 <70c977815af0d997feb2d0c5d284d55689bf7051 | e84d2e53a05c78a04d1343eeb0f31a79456e79fc, 3302aaeac4f7ee6b775850db21d5f61064ce70ad, 032746c2dd9a4ea0774b04ac8a29e2ea628f106e, c57001f55f97ef856fb6527e376c5c4a056a53a4, 70c977815af0d997feb2d0c5d284d55689bf7051 |
| Linux/Linuxgeneric | 6.5 | Not reported |
Published upstream
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 15, 2026
In the Linux kernel, the following vulnerability has been resolved: ALSA: ump: fix double free of out_cvts on rawmidi error snd_ump_attach_legacy_rawmidi() allocates the legacy conversion array ump->out_cvts and, on the snd_rawmidi_new() error path, frees it with kfree() but leaves ump->out_cvts pointing at the freed memory. When the endpoint is later torn down, snd_ump_endpoint_free() frees ump->out_cvts a second time, resulting in a double free. The host snd-usb-audio driver attaches the legacy rawmidi for any USB MIDI 2.0 (UMP) device, so a device that makes snd_rawmidi_new() fail reaches this path on enumeration. Clear ump->out_cvts after freeing it on the error path so it is not freed again during teardown. Discovered by XBOW, triaged by Baul Lee <[email protected]>
Quoted source text, attributed separately from HOL analysis.