7.8
CVE-2026-72261
- EPSS 0.16%
- Veröffentlicht 15.08.2026 05:54:49
- Zuletzt bearbeitet 17.08.2026 06:18:28
- Erkennungen
ASoC: SOF: ipc3-control: Validate size in snd_sof_update_control
In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: ipc3-control: Validate size in snd_sof_update_control In snd_sof_update_control(), firmware-provided cdata->num_elems is checked against local_cdata->data->size but never against the actual allocation size. If local_cdata->data->size was previously set to an inconsistent value, the memcpy could write past the allocated buffer. Add a bounds check to ensure num_elems fits within the available space in the ipc_control_data allocation before copying.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
10f461d79c2d1afb22344986cc1b4631169cf25e
Version <
1dc25a3e06364f48c4ef06016852f8b82425151a
Status
affected
Version
10f461d79c2d1afb22344986cc1b4631169cf25e
Version <
ee781058cd4d71e4449f41cbe6a3b8c59daa2c51
Status
affected
Version
10f461d79c2d1afb22344986cc1b4631169cf25e
Version <
ecf67f1302f2080b4d241b973364aacda70ad740
Status
affected
Version
10f461d79c2d1afb22344986cc1b4631169cf25e
Version <
d3abaedf6a58469610136d2dace1a85cddf7afcf
Status
affected
Version
10f461d79c2d1afb22344986cc1b4631169cf25e
Version <
2a591bf6fd41fd14bdae689aafac4a9ee702c23c
Status
affected
Version
10f461d79c2d1afb22344986cc1b4631169cf25e
Version <
390aa4c9339bb0ec0bc8d554e830faf93ca9d49e
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
5.18
Status
affected
Version
0
Version <
5.18
Status
unaffected
Version <=
6.1.*
Version
6.1.178
Status
unaffected
Version <=
6.6.*
Version
6.6.145
Status
unaffected
Version <=
6.12.*
Version
6.12.97
Status
unaffected
Version <=
6.18.*
Version
6.18.40
Status
unaffected
Version <=
7.1.*
Version
7.1.5
Status
unaffected
Version <=
*
Version
7.2
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.16% | 0.061 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
https://git.kernel.org/stable/c/1dc25a3e06364f48c4ef06016852f8b82425151a
https://git.kernel.org/stable/c/ee781058cd4d71e4449f41cbe6a3b8c59daa2c51
https://git.kernel.org/stable/c/ecf67f1302f2080b4d241b973364aacda70ad740
https://git.kernel.org/stable/c/d3abaedf6a58469610136d2dace1a85cddf7afcf
https://git.kernel.org/stable/c/2a591bf6fd41fd14bdae689aafac4a9ee702c23c
https://git.kernel.org/stable/c/390aa4c9339bb0ec0bc8d554e830faf93ca9d49e