7.8
CVE-2026-72302
- EPSS 0.18%
- Veröffentlicht 15.08.2026 05:55:21
- Zuletzt bearbeitet 17.08.2026 06:18:33
- Erkennungen
ASoC: SOF: ipc3-control: Use overflow checks in control_update size calc
In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: ipc3-control: Use overflow checks in control_update size calc In sof_ipc3_control_update(), the expected_size calculation uses firmware-provided cdata->num_elems in arithmetic that could overflow on 32-bit platforms, wrapping to a small value. This would allow the cdata->rhdr.hdr.size comparison to pass with mismatched sizes, potentially leading to out-of-bounds access in snd_sof_update_control. Use check_mul_overflow() and check_add_overflow() to detect and reject overflowed size calculations.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
10f461d79c2d1afb22344986cc1b4631169cf25e
Version <
6856b3c23b0995eefad5a6142b4365ef70e1fe4a
Status
affected
Version
10f461d79c2d1afb22344986cc1b4631169cf25e
Version <
89a2309a9eec80d4c19e3aed62c4f923594d1911
Status
affected
Version
10f461d79c2d1afb22344986cc1b4631169cf25e
Version <
ffd79e77f2fbacd7a5d40ad1d4c7f3f089a8f2f3
Status
affected
Version
10f461d79c2d1afb22344986cc1b4631169cf25e
Version <
711d912b18763af62a63aa8f2419a774eb63bba4
Status
affected
Version
10f461d79c2d1afb22344986cc1b4631169cf25e
Version <
312c7d2ebe696da3f885eee77d52297664e57c53
Status
affected
Version
10f461d79c2d1afb22344986cc1b4631169cf25e
Version <
8791977d7289f6e9d2b014f60a5455f053a7bc04
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
5.18
Status
affected
Version
0
Version <
5.18
Status
unaffected
Version <=
6.1.*
Version
6.1.178
Status
unaffected
Version <=
6.6.*
Version
6.6.145
Status
unaffected
Version <=
6.12.*
Version
6.12.97
Status
unaffected
Version <=
6.18.*
Version
6.18.40
Status
unaffected
Version <=
7.1.*
Version
7.1.5
Status
unaffected
Version <=
*
Version
7.2
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.18% | 0.076 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
https://git.kernel.org/stable/c/6856b3c23b0995eefad5a6142b4365ef70e1fe4a
https://git.kernel.org/stable/c/89a2309a9eec80d4c19e3aed62c4f923594d1911
https://git.kernel.org/stable/c/ffd79e77f2fbacd7a5d40ad1d4c7f3f089a8f2f3
https://git.kernel.org/stable/c/711d912b18763af62a63aa8f2419a774eb63bba4
https://git.kernel.org/stable/c/312c7d2ebe696da3f885eee77d52297664e57c53
https://git.kernel.org/stable/c/8791977d7289f6e9d2b014f60a5455f053a7bc04