-

CVE-2026-72300

ASoC: SOF: topology: validate vendor array size before parsing

In the Linux kernel, the following vulnerability has been resolved:

ASoC: SOF: topology: validate vendor array size before parsing

sof_parse_token_sets() reads array->size while iterating over topology
private data. The loop condition only checks that some data remains, so a
malformed topology with a truncated trailing vendor array can make the
parser read the size field before a full vendor-array header is available.

Validate that the remaining private data contains a complete
snd_soc_tplg_vendor_array header before reading array->size.

The declared array size check also needs to remain signed. asize is an int,
but sizeof(*array) has type size_t, so comparing them directly promotes
negative asize values to unsigned and lets them pass the check,
as reported in the stable review thread reference below.

Cast sizeof(*array) to int when validating the declared array size. This
rejects negative, zero and otherwise too-small sizes before the parser
dispatches to the tuple-specific code.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 5c37bd025068381f5bdbbf6a5ae3a1da8f6ed928
Version < 7c6d2d2baeb1e62dc8c6951d27edc16c5ea6e3aa
Status affected
Version 06d4938e41d62af7b5b3f39eb239f58b21f50443
Version < a40e250414b463e953c54cd2a829c9a9a49a78c3
Status affected
Version 55024322915539098f7a7dd318351c7a003ff041
Version < d34deef34c99bb4b3ebd2ac51058857827a20e7e
Status affected
Version 215e5fe75881a7e2425df04aeeed47a903d5cd5d
Version < 201b60c4d15538fcc3c0c2ea9b75dd7d0f58022c
Status affected
Version 215e5fe75881a7e2425df04aeeed47a903d5cd5d
Version < 8468dd79cfb2ffbdeaf7c353f63d64941cb8ba05
Status affected
Version 756c48bdf23050def518e85929be6edea9ae6823
Status affected
Version 6.6.136
Version < 6.6.145
Status affected
Version 6.12.83
Version < 6.12.97
Status affected
Version 6.18.24
Version < 6.18.40
Status affected
Version 6.19.14
Version < 6.20
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 7.0
Status affected
Version 0
Version < 7.0
Status unaffected
Version <= 6.6.*
Version 6.6.145
Status unaffected
Version <= 6.12.*
Version 6.12.97
Status unaffected
Version <= 6.18.*
Version 6.18.40
Status unaffected
Version <= 7.1.*
Version 7.1.5
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.2% 0.102
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/7c6d2d2baeb1e62dc8c6951d27edc16c5ea6e3aa
https://git.kernel.org/stable/c/a40e250414b463e953c54cd2a829c9a9a49a78c3
https://git.kernel.org/stable/c/d34deef34c99bb4b3ebd2ac51058857827a20e7e
https://git.kernel.org/stable/c/201b60c4d15538fcc3c0c2ea9b75dd7d0f58022c
https://git.kernel.org/stable/c/8468dd79cfb2ffbdeaf7c353f63d64941cb8ba05