7.8

CVE-2026-72301

ASoC: SOF: ipc3-control: Fix TOCTOU in bytes_put and bytes_get

In the Linux kernel, the following vulnerability has been resolved:

ASoC: SOF: ipc3-control: Fix TOCTOU in bytes_put and bytes_get

In sof_ipc3_bytes_put(), the size used for the memcpy is derived from
the old data->size already in the buffer, not the incoming new data's
size field. If the new data has a different size, the copy length is
wrong: it may truncate valid data or copy stale bytes.

Similarly, sof_ipc3_bytes_get() checks data->size against max_size
without accounting for the sizeof(struct sof_ipc_ctrl_data) offset
of the flex array within the allocation.

Fix bytes_put to validate and use the incoming data's sof_abi_hdr.size
from ucontrol before copying. Fix bytes_get to subtract sizeof(*cdata)
from the bounds check to match the actual available space.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 544ac8858f249950b4d99c68e538cdc07300528f
Version < 8bd715a9d882fe1993bb2aec5eff89fffa946592
Status affected
Version 544ac8858f249950b4d99c68e538cdc07300528f
Version < 0dce240145f47545d2e4b18c6d58033b83e1fd0e
Status affected
Version 544ac8858f249950b4d99c68e538cdc07300528f
Version < ed4f758f34be4c32e02933ac4fa044589d9c1c16
Status affected
Version 544ac8858f249950b4d99c68e538cdc07300528f
Version < 0c4fbdaca225b97122b61b68c5353caa33a253c3
Status affected
Version 544ac8858f249950b4d99c68e538cdc07300528f
Version < 92f90917413bdd6078fefff6f6c83a07bf870b04
Status affected
Version 544ac8858f249950b4d99c68e538cdc07300528f
Version < 1f97760417b5faa60e9642fd0ed61eb17d0b1b39
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 5.18
Status affected
Version 0
Version < 5.18
Status unaffected
Version <= 6.1.*
Version 6.1.178
Status unaffected
Version <= 6.6.*
Version 6.6.145
Status unaffected
Version <= 6.12.*
Version 6.12.97
Status unaffected
Version <= 6.18.*
Version 6.18.40
Status unaffected
Version <= 7.1.*
Version 7.1.5
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.16% 0.061
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/8bd715a9d882fe1993bb2aec5eff89fffa946592
https://git.kernel.org/stable/c/0dce240145f47545d2e4b18c6d58033b83e1fd0e
https://git.kernel.org/stable/c/ed4f758f34be4c32e02933ac4fa044589d9c1c16
https://git.kernel.org/stable/c/0c4fbdaca225b97122b61b68c5353caa33a253c3
https://git.kernel.org/stable/c/92f90917413bdd6078fefff6f6c83a07bf870b04
https://git.kernel.org/stable/c/1f97760417b5faa60e9642fd0ed61eb17d0b1b39