CVE-2026-74497 evidence review
Linux
In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Clamp frame size in implicit-feedback mode snd_usb_handle_sync_urb() scales received sync packet sizes by the sender's stride and stores the result directly in out_packet->packet_size[i]. If a connected USB device sends an oversized sync packet, this frame count can exceed ep->maxframesize. The un-clamped frame count then propagates to the playback endpoint queue, potentially driving packet transfers beyond the endpoint's hardware frame limits. Cap the calculated frame count against ep->maxframesize in snd_...
This record remains available for product and version identification, but it is not presented as a complete remediation procedure. Confirm the affected range and the supported fix in a direct vendor advisory before changing production systems.
Identify the product and installed version
Record whether Linux is present, where it is installed, and which interfaces are exposed.
- Record the product name, package or appliance identifier, and installed version.
- Identify internet-facing, administrative, API, and internal access paths.
- Preserve the pre-change configuration and relevant service logs.
Compare the affected range
Use the current record as an identification aid: >= 28acb12014fb0c3e1edfdab1b1e3e266cf651550 < 2d39fea6d3c19a2f5811d123114d92e3d0115fd1, >= 28acb12014fb0c3e1edfdab1b1e3e266cf651550 < 09cf3dbbb4256a43feb91d2f51f274510a9ada47, >= 28acb12014fb0c3e1edfdab1b1e3e266cf651550 < cfa8d3e0e8b812c4db4d5241f62b6bdbab2bd7be, >= 28acb12014fb0c3e1edfdab1b1e3e266cf651550 < 56ac3e7c90f6b45969c3fd07a98fad760ffd6901, >= 28acb12014fb0c3e1edfdab1b1e3e266cf651550 < be97fea7451d758881b95af78e900dd0d58a382a, >= 28acb12014fb0c3e1edfdab1b1e3e266cf651550 < 2db4535d6af79276a64449201c5be5feffb31c64, >= 28acb12014fb0c3e1edfdab1b1e3e266cf651550 < 53f0aa37eb945f3c983f61d12fc35eb33debb8a9, >= 28acb12014fb0c3e1edfdab1b1e3e266cf651550 < 8d7a30c50c2e58a6839634ed0acde14466d1dc61, >= 3.8. Resolve incomplete inventory results before deciding that an asset is unaffected.
Verify the authoritative remediation source
Open the linked source material and locate a direct vendor advisory for this CVE. Confirm the supported fixed release and product-specific update path before making a production change.
Operational boundary
This page does not replace the vendor advisory, support contract, change-management process, or recovery plan. Do not infer that an asset is unaffected from an incomplete inventory query or a missing fixed-version field.