7.8

CVE-2026-72262

ASoC: SOF: ipc3-control: Fix heap overflow in bytes_ext put/get

In the Linux kernel, the following vulnerability has been resolved:

ASoC: SOF: ipc3-control: Fix heap overflow in bytes_ext put/get

The ipc_control_data buffer is allocated as kzalloc(max_size), where
max_size covers the entire struct sof_ipc_ctrl_data including its
flexible array payload. However, the bounds checks in bytes_ext_put
and _bytes_ext_get compared user data lengths against max_size
directly, ignoring that cdata->data sits at an offset of
sizeof(struct sof_ipc_ctrl_data) bytes into the allocation.

This allowed writing up to sizeof(struct sof_ipc_ctrl_data) bytes past
the end of the heap buffer from unprivileged userspace via the ALSA TLV
kcontrol interface, and similarly allowed over-reading adjacent heap
data on the get path.

Fix all bounds checks to subtract sizeof(*cdata) from max_size so they
reflect the actual space available at the cdata->data offset. Also fix
the error-path restore in bytes_ext_put which wrote to cdata->data
instead of cdata, causing the same overflow.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 67ec2a091630c28ea8d05db2bd7178a05b04b7e6
Version < af4b437a463ac0482ba705434a44da06783778e6
Status affected
Version 67ec2a091630c28ea8d05db2bd7178a05b04b7e6
Version < 1adde1941bba7b0d7104b86ed819d48d81cb0ad9
Status affected
Version 67ec2a091630c28ea8d05db2bd7178a05b04b7e6
Version < eaa67e139c9217099e2a7b717aeeb46c65de3494
Status affected
Version 67ec2a091630c28ea8d05db2bd7178a05b04b7e6
Version < 121577383b5cf221e86581e0f2bcca4c66f17469
Status affected
Version 67ec2a091630c28ea8d05db2bd7178a05b04b7e6
Version < f4933e1d11b97b6a0951648b7c3e53850e1b33a9
Status affected
Version 67ec2a091630c28ea8d05db2bd7178a05b04b7e6
Version < fd46668d538993218eea19c6925c868ac0f2630c
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 5.18
Status affected
Version 0
Version < 5.18
Status unaffected
Version <= 6.1.*
Version 6.1.184
Status unaffected
Version <= 6.6.*
Version 6.6.145
Status unaffected
Version <= 6.12.*
Version 6.12.97
Status unaffected
Version <= 6.18.*
Version 6.18.40
Status unaffected
Version <= 7.1.*
Version 7.1.5
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.18% 0.075
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/1adde1941bba7b0d7104b86ed819d48d81cb0ad9
https://git.kernel.org/stable/c/eaa67e139c9217099e2a7b717aeeb46c65de3494
https://git.kernel.org/stable/c/121577383b5cf221e86581e0f2bcca4c66f17469
https://git.kernel.org/stable/c/f4933e1d11b97b6a0951648b7c3e53850e1b33a9
https://git.kernel.org/stable/c/fd46668d538993218eea19c6925c868ac0f2630c
https://git.kernel.org/stable/c/af4b437a463ac0482ba705434a44da06783778e6